Impact
The SMS Alert WordPress plugin fails to verify that an administrator has permission to manage the selected users before revealing their billing phone numbers. This flaw allows a privileged administrator to expose contact information for users belonging to other sites within the same multisite network, compromising confidentiality of personal data without requiring additional credentials.
Affected Systems
All installations of the SMS Alert plugin earlier than version 4.0.1 running on WordPress multisite networks are affected. The vulnerability requires that the attacker be a network administrator on one site and that the plugin’s gateway credentials are stored on that site. Only multisite deployments are at risk.
Risk and Exploitability
The vulnerability is an information‑disclosure error with a CVSS score calculated by the CNA (not provided). The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, indicating that it has not been observed as a commonly exploited vulnerability. However, because the flaw can be triggered by a legitimate administrator account, an attacker who has already obtained such access can readily disclose users’ billing phone numbers. The attack vector is local to the Wordpress installation; remote exploitation is not required.
OpenCVE Enrichment