PT-2026-109539 · WordPress · Sms Alert
CVE-2026-94256
·
Published
2026-10-10
·
Updated
2026-10-10
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SMS Alert versions prior to 4.0.1
Description
An authentication bypass exists where the plugin fails to verify if the account attempting to log in is the actual owner of the verified one-time code. This allows unauthenticated attackers to sign in as any user who has a stored phone number, including administrators, by completing a code challenge using a phone under the attacker's control.
Recommendations
Update SMS Alert to version 4.0.1 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sms Alert