CVE-2026-15014
Received Received - Intake

Authentication Bypass in SMS Alert WooCommerce Plugin

Vulnerability report for CVE-2026-15014, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Wordfence

Description

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before issuing an authentication cookie β€” the flag is set to `true` after any successful OTP validation without being bound to the specific phone number that was verified. This makes it possible for unauthenticated attackers to complete OTP verification for a phone number they control, then resubmit the registration request with a victim's `billing_phone` value to have `wp_set_auth_cookie()` called for the resolved victim account, enabling full authentication as any existing WordPress user whose registered phone number is known or guessable, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce sms_alert to 3.9.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass flaw in the SMS Alert WordPress plugin. It allows attackers to take over any WordPress account by exploiting a session flag that isn't tied to a specific phone number. The attacker verifies their own phone number via OTP, then submits a registration request with a victim's phone number to gain access to their account.

Impact Analysis

If you use this plugin, an attacker could gain full access to your WordPress account, including admin accounts. This could lead to unauthorized changes, data theft, or complete site takeover. The impact is severe as it affects all versions up to 3.9.7.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using this plugin may face compliance breaches, legal penalties, and reputational damage.

Mitigation Strategies

Immediately update the SMS Alert – SMS & OTP for WooCommerce plugin to the latest version beyond 3.9.7. If an update is not available, consider disabling the plugin until a patch is released. Review WordPress user accounts for unauthorized access and reset credentials for any potentially compromised accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15014. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart