top of page
perceptive_background_267k.jpg

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to …

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 17:04:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-15014 affects the SMS Alert – SMS & OTP for WooCommerce plugin for WordPress in all versions up to and including 3.9.7. The vulnerability allows unauthenticated attackers to bypass authentication and take over arbitrary user accounts, including administrators. The root cause is a logic flaw in the processRegistration() function, which uses a session-level boolean flag ($_SESSION['sa_mobile_verified']) to confirm OTP verification without binding it to the specific phone number that was verified. An attacker can verify OTP for a phone number they control, then swap in a victim's billing_phone value to trigger wp_set_auth_cookie() for the victim's account. This results in full authentication as any WordPress user whose phone number is known or guessable. The vulnerability requires no prior authentication and can lead to complete site compromise if an administrator account is targeted.

Technical details

Mitigation steps:

Affected products:

SMS Alert – SMS & OTP for WooCommerce plugin for WordPress (versions up to and including 3.9.7)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page