Description
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. This is only vulnerable on sites with OTP verification for password resets enabled, and where the administrator (or other user) has set a phone number for OTP verification.
Published: 2026-07-01
Score: 9.8 Critical
EPSS: 2.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SMS Alert – SMS & OTP for WooCommerce plugin does not properly validate a user's identity before allowing changes to account details such as email or password. As a result, an unauthenticated attacker can change any user's email address and then trigger a password reset, ultimately gaining full control of that account. This flaw allows privilege escalation to administrator accounts, potentially compromising the entire WordPress site. The vulnerability only exists on sites that have OTP password reset enabled and where at least one user has a phone number registered for OTP verification, but it is present in all plugin versions up to 3.9.5.

Affected Systems

The flaw affects WordPress installations that run CozyVision1’s SMS Alert plugin version 3.9.5 or older. It requires the site to have OTP password reset enabled and phone numbers configured for users (especially administrators). The vulnerability applies to all affected releases regardless of other security settings.

Risk and Exploitability

The CVSS score of 9.8 reflects critical severity; the EPSS score of 2% indicates a measurable yet modest likelihood of exploitation. The flaw is not yet listed in CISA’s KEV catalog. Attackers can exercise the vulnerability over the web by submitting crafted requests to the email change and password reset endpoints, exploiting the absent identity check. Based on the description, it is inferred that the likely attack vector is remote HTTP requests to the plugin’s endpoints, which an attacker can perform without needing to authenticate. Because the vulnerability allows unrestricted privilege escalation, the potential impact on confidentiality, integrity, and availability is global to the affected WordPress site.

Generated by OpenCVE AI on August 25, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SMS Alert plugin to a version newer than 3.9.5 where this vulnerability has been fixed.
  • If an update cannot be performed immediately, disable OTP password reset functionality or prevent users from having phone numbers for OTP, as the flaw requires OTP verification to be active.
  • Monitor site logs for suspicious email change or password reset attempts and block offending IP addresses.

Generated by OpenCVE AI on August 25, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Cozyvision1
Cozyvision1 sms Alert – Sms & Otp For Woocommerce, Order Notifications & Abandoned Cart Recovery
Wordpress
Wordpress wordpress
Vendors & Products Cozyvision1
Cozyvision1 sms Alert – Sms & Otp For Woocommerce, Order Notifications & Abandoned Cart Recovery
Wordpress
Wordpress wordpress

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. This is only vulnerable on sites with OTP verification for password resets enabled, and where the administrator (or other user) has set a phone number for OTP verification.
Title SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cozyvision1 Sms Alert – Sms & Otp For Woocommerce, Order Notifications & Abandoned Cart Recovery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-01T10:32:03.955Z

Reserved: 2026-06-05T15:14:38.745Z

Link: CVE-2026-11387

cve-icon Vulnrichment

Updated: 2026-07-01T10:30:31.699Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T08:16:20.587

Modified: 2026-07-01T13:56:17.493

Link: CVE-2026-11387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T16:30:06Z

Weaknesses