SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15014

CRITICAL · CVSS 9.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The SMS Alert plugin for WordPress is vulnerable to an authentication bypass that allows attackers to take over accounts by exploiting the `billing_phone` parameter. This flaw arises from the improper handling of session verification, enabling unauthenticated users to gain access to any WordPress account linked to a known or guessable phone number. WordPress site administrators and users of the affected plugin should prioritize patching this vulnerability to prevent potential account compromises.

CVE
CVE-2026-15014
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%
WordPress

Original NVD Description

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before issuing an authentication cookie — the flag is set to `true` after any successful OTP validation without being bound to the specific phone number that was verified. This makes it possible for unauthenticated attackers to complete OTP verification for a phone number they control, then resubmit the registration request with a victim's `billing_phone` value to have `wp_set_auth_cookie()` called for the resolved victim account, enabling full authentication as any existing WordPress user whose registered phone number is known or guessable, including administrators.