Impact
An unauthenticated attacker can leverage a flaw in the WordPress SMS Alert Order Notifications plugin versions 3.9.7 and earlier to elevate privileges and execute actions normally restricted to privileged users. The weakness corresponds to CWE-266, causing the application to bypass authorization checks. If exploited, the attacker may alter or delete site content, configure plugin settings, or even install additional malicious plugins, resulting in a complete takeover of the site.
Affected Systems
The vulnerability affects the SMS Alert Order Notifications plugin distributed by Cozy Vision Technologies Pvt. Ltd. Versions up to and including 3.9.7 are impacted. Any WordPress installation that has not been updated beyond 3.9.7 and lacks the plugin installed by a verified source is at risk.
Risk and Exploitability
The CVSS score of 9.8 signifies critical severity, and although the EPSS score is not available, the lack of authentication hints that exploitation is feasible without prior credentials. The exploit can be conducted remotely via the web interface, making it an obvious target for attackers. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score warrants immediate attention. Based on the description, the likely attack vector is a direct HTTP request to the plugin’s endpoint that bypasses role checks, leading to elevated privileges across the WordPress environment.
OpenCVE Enrichment