PT-2026-65403 · WordPress · Sms Alert – Sms & Otp For Woocommerce
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery versions prior to 3.9.8
Description
An authentication bypass exists that allows for account takeover via the
billing phone parameter. The issue occurs because the processRegistration() function relies on a $ SESSION['sa mobile verified'] boolean flag to issue an authentication cookie. Since this flag is not bound to a specific phone number, an unauthenticated attacker can verify a phone number they control to set the flag to true, and then resubmit the registration request using a victim's billing phone. This triggers the wp set auth cookie() function for the victim's account, granting the attacker full access to any WordPress user account with a known or guessable phone number, including administrator accounts.Recommendations
Update the plugin to a version newer than 3.9.7.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sms Alert – Sms & Otp For Woocommerce