PT-2026-67061 · WordPress · Sms Alert
CVE-2026-15206
·
Published
2026-08-02
·
Updated
2026-08-02
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SMS Alert WordPress plugin versions prior to 3.9.8
Description
An issue exists where the plugin fails to bind the mobile verified session flag to the phone number that underwent verification. An unauthenticated attacker can verify a One-Time Password (OTP) sent to their own device and then provide a different phone number during the signup or login process. This allows the attacker to select and log into any account, including administrator accounts, provided the target user has a billing phone number on file.
Recommendations
Update SMS Alert WordPress plugin to version 3.9.8 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sms Alert