Impact
The SMS Alert Order Notifications plugin contains a privilege escalation flaw that allows a user with subscriber-level access to acquire higher privileges within the WordPress installation. The vulnerability is driven by insufficient authorization checks (CWE-266), letting the attacker bypass restrictions during certain plugin actions and assume roles such as editor or administrator, enabling configuration changes, data exposure, or persistent exploitation.
Affected Systems
Cozy Vision Technologies Pvt. Ltd. develops the WordPress SMS Alert Order Notifications plugin. Versions 3.9.9 and earlier are vulnerable and are used on WordPress sites that rely on the plugin’s order notification functionality.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is less than 1%, implying a low probability of exploitation at present. Because the flaw permits escalation from subscriber to any higher role, an attacker with local or remote WordPress access can gain administrator rights, leading to full takeover of the site. The CVE is not listed in the CISA KEV catalog, but the high impact warrants immediate attention.
OpenCVE Enrichment