PT-2026-65403 · WordPress · Sms Alert – Sms & Otp For Woocommerce

·

CVE-2026-15014

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery versions prior to 3.9.8
Description An authentication bypass exists that allows for account takeover via the billing phone parameter. The issue occurs because the processRegistration() function relies on a $ SESSION['sa mobile verified'] boolean flag to issue an authentication cookie. Since this flag is not bound to a specific phone number, an unauthenticated attacker can verify a phone number they control to set the flag to true, and then resubmit the registration request using a victim's billing phone. This triggers the wp set auth cookie() function for the victim's account, granting the attacker full access to any WordPress user account with a known or guessable phone number, including administrator accounts.
Recommendations Update the plugin to a version newer than 3.9.7.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15014

Affected Products

Sms Alert – Sms & Otp For Woocommerce