CVE-2026-94258
Received Received - Intake

Information Disclosure in SMS Alert WordPress Plugin

Vulnerability report for CVE-2026-94258, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown SMS Alert 3.6.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the SMS Alert WordPress plugin versions 3.6.4 to 4.0.0 in multisite installations. It allows an administrator of one site on a network to disclose billing phone numbers of users on other sites in the same network. The plugin fails to check if the administrator has permission to manage those users before returning their stored phone numbers.

Detection Guidance

Check if the SMS Alert plugin version is between 3.6.4 and 4.0.0 in a WordPress multisite installation. Verify if an administrator can access billing phone numbers of users from other sites on the network.

Impact Analysis

If you use the SMS Alert plugin in a WordPress multisite setup with versions 3.6.4 to 4.0.0, an administrator on one site could access and disclose the billing phone numbers of users on other sites in the network. This could lead to privacy breaches and unauthorized data exposure.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal data such as phone numbers. Unauthorized disclosure of such data may result in legal penalties and reputational damage.

Mitigation Strategies

Update the SMS Alert plugin to version 4.0.1 or later immediately to patch the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94258. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart