top of page
perceptive_background_267k.jpg

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to …

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 09:01:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-15014 is a critical authentication bypass vulnerability in the SMS Alert WordPress plugin (versions up to and including 3.9.7). The flaw exists in the processRegistration() function, which relies on a session boolean flag $_SESSION['sa_mobile_verified'] that is set to true upon any successful OTP validation, without binding it to the specific phone number that was verified. An unauthenticated attacker can exploit this by completing OTP verification with a phone number they control, then resubmitting the registration request with a victim's billing_phone value. This causes wp_set_auth_cookie() to be called for the victim's account, granting full authentication. The vulnerability enables complete account takeover for any WordPress user whose phone number is known or guessable, including administrators. A patch was introduced in changeset 3623914 of the sms-alert plugin repository.

Technical details

Mitigation steps:

Affected products:

SMS Alert – SMS & OTP for WooCommerce plugin for WordPress (versions up to and including 3.9.7)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page