


Perceptive Security
SOC/SIEM Consultancy

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to …
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 19:04:58
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
CVE-2026-15014 affects the SMS Alert – SMS & OTP for WooCommerce plugin for WordPress in all versions up to and including 3.9.7. The vulnerability allows unauthenticated attackers to bypass authentication and take over arbitrary user accounts, including administrators. The root cause is a logic flaw in the processRegistration() function, which uses a session-level boolean flag ($_SESSION['sa_mobile_verified']) to confirm OTP verification without binding it to the specific phone number that was verified. An attacker can verify OTP for a phone number they control, then swap in a victim's billing_phone value to trigger wp_set_auth_cookie() for the victim's account. This results in full authentication as any WordPress user whose phone number is known or guessable. The vulnerability requires no prior authentication and can lead to complete site compromise if an administrator account is targeted.
Technical details
Mitigation steps:
Affected products:
SMS Alert – SMS & OTP for WooCommerce plugin for WordPress (versions up to and including 3.9.7)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15014
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/FormInterface.php#L56
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L252
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L602
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L680
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L691
https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&new=3623914%40sms-alert
https://www.wordfence.com/threat-intel/vulnerabilities/id/661d4ea9-572d-4544-b5cf-39fd69c104a6?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
