


Perceptive Security
SOC/SIEM Consultancy

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to …
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 09:01:12
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
CVE-2026-15014 is a critical authentication bypass vulnerability in the SMS Alert WordPress plugin (versions up to and including 3.9.7). The flaw exists in the processRegistration() function, which relies on a session boolean flag $_SESSION['sa_mobile_verified'] that is set to true upon any successful OTP validation, without binding it to the specific phone number that was verified. An unauthenticated attacker can exploit this by completing OTP verification with a phone number they control, then resubmitting the registration request with a victim's billing_phone value. This causes wp_set_auth_cookie() to be called for the victim's account, granting full authentication. The vulnerability enables complete account takeover for any WordPress user whose phone number is known or guessable, including administrators. A patch was introduced in changeset 3623914 of the sms-alert plugin repository.
Technical details
Mitigation steps:
Affected products:
SMS Alert – SMS & OTP for WooCommerce plugin for WordPress (versions up to and including 3.9.7)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15014
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/FormInterface.php#L56
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L252
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L602
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L680
https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L691
https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&new=3623914%40sms-alert
https://www.wordfence.com/threat-intel/vulnerabilities/id/661d4ea9-572d-4544-b5cf-39fd69c104a6?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
