PT-2026-109539 · WordPress · Sms Alert

CVE-2026-94256

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SMS Alert versions prior to 4.0.1
Description An authentication bypass exists where the plugin fails to verify if the account attempting to log in is the actual owner of the verified one-time code. This allows unauthenticated attackers to sign in as any user who has a stored phone number, including administrators, by completing a code challenge using a phone under the attacker's control.
Recommendations Update SMS Alert to version 4.0.1 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94256

Affected Products

Sms Alert