Impact
An unauthenticated privilege escalation flaw exists in the WordPress SMS Alert Order Notifications plugin, versions three point nine point six and earlier. The vulnerability allows a user without any site credentials to gain administrative privileges, enabling full control over the site. The weakness corresponds to CWE‑266, improper authorization control.
Affected Systems
The affected product is the SMS Alert Order Notifications plugin developed by Cozy Vision Technologies Pvt. Ltd. Versions up to and including 3.9.6 are vulnerable. Site operators using any of these versions should treat the plugin as a potential privilege escalation vector until it is upgraded.
Risk and Exploitability
The CVSS base score of 9.8 marks the issue as critical, and while the EPSS score is under 1%, the low probability reflects a currently small exploitation window; however, the lack of a KEV listing does not diminish the importance of the flaw. Based on the description, it is inferred that an attacker can trigger the flaw by sending any request to the plugin's endpoints without authenticating, which then escalates privileges without needing prior credentials.
OpenCVE Enrichment