Impact
The SMS Alert – SMS & OTP for WooCommerce plugin does not properly validate a user's identity before allowing changes to account details such as email or password. As a result, an unauthenticated attacker can change any user's email address and then trigger a password reset, ultimately gaining full control of that account. This flaw allows privilege escalation to administrator accounts, potentially compromising the entire WordPress site. The vulnerability only exists on sites that have OTP password reset enabled and where at least one user has a phone number registered for OTP verification, but it is present in all plugin versions up to 3.9.5.
Affected Systems
The flaw affects WordPress installations that run CozyVision1’s SMS Alert plugin version 3.9.5 or older. It requires the site to have OTP password reset enabled and phone numbers configured for users (especially administrators). The vulnerability applies to all affected releases regardless of other security settings.
Risk and Exploitability
The CVSS score of 9.8 reflects critical severity; the EPSS score of 2% indicates a measurable yet modest likelihood of exploitation. The flaw is not yet listed in CISA’s KEV catalog. Attackers can exercise the vulnerability over the web by submitting crafted requests to the email change and password reset endpoints, exploiting the absent identity check. Based on the description, it is inferred that the likely attack vector is remote HTTP requests to the plugin’s endpoints, which an attacker can perform without needing to authenticate. Because the vulnerability allows unrestricted privilege escalation, the potential impact on confidentiality, integrity, and availability is global to the affected WordPress site.
OpenCVE Enrichment