PT-2026-54508 · WordPress · Sms Alert
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery versions prior to 3.9.6
Description
An issue exists that allows unauthenticated attackers to perform privilege escalation via account takeover. The plugin fails to properly validate a user's identity before updating account details, such as resetting passwords. This allows an attacker to change the email addresses of arbitrary users, including administrators, to reset their passwords and gain full account access. This issue specifically affects sites where OTP (One-Time Password) verification for password resets is enabled and the target user has a phone number configured for OTP verification.
Recommendations
Update the plugin to version 3.9.6 or later.
Fix
LPE
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sms Alert