top of page
perceptive_background_267k.jpg

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to …

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 11:01:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-15014 is a critical authentication bypass vulnerability in the SMS Alert WordPress plugin (versions up to and including 3.9.7). The flaw exists in the processRegistration() function, which relies on a session boolean flag $_SESSION['sa_mobile_verified'] that is set to true upon any successful OTP validation, without binding it to the specific phone number that was verified. An unauthenticated attacker can exploit this by completing OTP verification with a phone number they control, then resubmitting the registration request with a victim's billing_phone value. This causes wp_set_auth_cookie() to be called for the victim's account, granting full authentication. The vulnerability enables complete account takeover for any WordPress user whose phone number is known or guessable, including administrators. A patch was introduced in changeset 3623914 of the sms-alert plugin repository.

Technical details

Mitigation steps:

Affected products:

SMS Alert – SMS & OTP for WooCommerce plugin for WordPress (versions up to and including 3.9.7)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page