CVE-2026-15206
Received Received - Intake

Unauthenticated Account Takeover via SMS Verification in SMS Alert WordPress Plugin

Vulnerability report for CVE-2026-15206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sms_alert wordpress_plugin to 3.9.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the SMS Alert WordPress plugin before version 3.9.8. It allows an attacker to bypass the verification process by exploiting a flaw where the session flag for a verified mobile number is not properly linked to the actual verified phone number. After verifying an OTP with their own phone, the attacker can then log in as any user, including administrators, by supplying a different phone number during the login process.

Detection Guidance

This vulnerability can be detected by checking the version of the SMS Alert WordPress plugin. If the version is below 3.9.8, the system is vulnerable. No specific commands are provided in the context to detect this issue.

Impact Analysis

If you use the SMS Alert plugin before version 3.9.8, an unauthenticated attacker could gain unauthorized access to your WordPress account, including administrator accounts. This could lead to full control over your website, data theft, or malicious modifications. Users with billing phone numbers on file are particularly at risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating compliance requirements under GDPR and HIPAA. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. A breach could result in legal penalties, fines, and reputational damage due to non-compliance.

Mitigation Strategies

Update the SMS Alert WordPress plugin to version 3.9.8 or later to fix the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart