Vulnerability Description
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before issuing an authentication cookie — the flag is set to `true` after any successful OTP validation without being bound to the specific phone number that was verified. This makes it possible for unauthenticated attackers to complete OTP verification for a phone number they control, then resubmit the registration request with a victim's `billing_phone` value to have `wp_set_auth_cookie()` called for the resolved victim account, enabling full authentication as any existing WordPress user whose registered phone number is known or guessable, including administrators.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/Fo
- https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/wo
- https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/wo
- https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/wo
- https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/wo
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&n
- https://www.wordfence.com/threat-intel/vulnerabilities/id/661d4ea9-572d-4544-b5c
FAQ
What is CVE-2026-15014?
CVE-2026-15014 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, ...
How severe is CVE-2026-15014?
CVE-2026-15014 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-15014?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.