PT-2026-54508 · WordPress · Sms Alert

·

CVE-2026-11387

·

Published

2026-06-30

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery versions prior to 3.9.6
Description An issue exists that allows unauthenticated attackers to perform privilege escalation via account takeover. The plugin fails to properly validate a user's identity before updating account details, such as resetting passwords. This allows an attacker to change the email addresses of arbitrary users, including administrators, to reset their passwords and gain full account access. This issue specifically affects sites where OTP (One-Time Password) verification for password resets is enabled and the target user has a phone number configured for OTP verification.
Recommendations Update the plugin to version 3.9.6 or later.

Fix

LPE

RCE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11387

Affected Products

Sms Alert