Description
The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network.
This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure of user billing phone numbers
Action: Apply Patch
AI Analysis

Impact

The SMS Alert WordPress plugin fails to verify that an administrator has permission to manage the selected users before revealing their billing phone numbers. This flaw allows a privileged administrator to expose contact information for users belonging to other sites within the same multisite network, compromising confidentiality of personal data without requiring additional credentials.

Affected Systems

All installations of the SMS Alert plugin earlier than version 4.0.1 running on WordPress multisite networks are affected. The vulnerability requires that the attacker be a network administrator on one site and that the plugin’s gateway credentials are stored on that site. Only multisite deployments are at risk.

Risk and Exploitability

The vulnerability is an information‑disclosure error with a CVSS score calculated by the CNA (not provided). The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, indicating that it has not been observed as a commonly exploited vulnerability. However, because the flaw can be triggered by a legitimate administrator account, an attacker who has already obtained such access can readily disclose users’ billing phone numbers. The attack vector is local to the Wordpress installation; remote exploitation is not required.

Generated by OpenCVE AI on October 8, 2026 at 07:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SMS Alert plugin to version 4.0.1 or later.
  • If upgrade is not feasible, remove or disable the plugin to prevent exposure of billing phone numbers.
  • Verify that gateway credentials are not stored on sites that host administrators of other sites, and consider revoking or rotating them if they are present.

Generated by OpenCVE AI on October 8, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
Title SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:09.230Z

Reserved: 2026-09-21T09:02:50.281Z

Link: CVE-2026-94258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:47.143

Modified: 2026-10-08T06:16:47.143

Link: CVE-2026-94258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses