Description
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.
Published: 2025-11-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows a user to exploit incorrectly configured access control settings within the Cozy Vision SMS Alert Order Notifications plugin. Because the plugin does not properly verify the privileges of a requester before allowing configuration changes, an attacker can gain unauthorized access to sensitive settings. This flaw is classified as CWE-862 and can lead to the compromise of the plugin’s configuration, potentially enabling additional malicious activity such as spamming or the manipulation of order notifications.

Affected Systems

The flaw affects the WordPress plugin SMS Alert Order Notifications, distributed by Cozy Vision. All versions from the earliest available build up to and including 3.8.8 are impacted. The plugin is used on WordPress sites, but no specific WordPress core version is listed as a requirement.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating moderate severity. Its EPSS score is less than 1%, meaning actual exploitation likelihood is very low, and it is not listed in the Cybersecurity and Infrastructure Security Agency’s KEV catalog. Attacks would likely target the plugin’s administrative interface, requiring authenticated access to reach the sensitive settings page; however, the missing authorization check removes the usual privilege barrier, so an attacker with any level of access that bypasses the normal WordPress role checks could exploit the flaw. While the risk is not high, the potential for unauthorized configuration changes warrants timely remediation.

Generated by OpenCVE AI on April 29, 2026 at 19:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SMS Alert Order Notifications plugin to a version newer than 3.8.8.
  • If an update cannot be implemented immediately, restrict access to the plugin’s settings page by assigning limited capabilities or using a role‑management plugin to prevent unauthorized users from reaching the vulnerable configuration area.
  • Review the plugin’s configuration after applying the update or restriction to confirm that all security settings are correctly applied and not exposed to users without appropriate authority.

Generated by OpenCVE AI on April 29, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Cozyvision
Cozyvision sms Alert Order Notifications
Wordpress
Wordpress wordpress
Vendors & Products Cozyvision
Cozyvision sms Alert Order Notifications
Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.
Title WordPress SMS Alert Order Notifications plugin <= 3.8.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Cozyvision Sms Alert Order Notifications
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:16.345Z

Reserved: 2025-11-21T11:21:04.794Z

Link: CVE-2025-66086

cve-icon Vulnrichment

Updated: 2025-11-21T21:39:17.417Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:49.760

Modified: 2026-04-27T18:16:34.670

Link: CVE-2025-66086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:00:18Z

Weaknesses