CVE-2026-15014
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before issuing an authentication cookie — the flag is set to `true` after any successful OTP validation without being bound to the specific phone number that was verified. This makes it possible for unauthenticated attackers to complete OTP verification for a phone number they control, then resubmit the registration request with a victim's `billing_phone` value to have `wp_set_auth_cookie()` called for the resolved victim account, enabling full authentication as any existing WordPress user whose registered phone number is known or guessable, including administrators.
| CWE | CWE-288 |
| Vendor | cozyvision1 |
| Product | sms alert – sms & otp for woocommerce, order notifications & abandoned cart recovery |
| Published | Jul 28, 2026 |
Get instant alerts for cozyvision1 sms alert – sms & otp for woocommerce, order notifications & abandoned cart recovery
Be the first to know when new critical vulnerabilities affecting cozyvision1 sms alert – sms & otp for woocommerce, order notifications & abandoned cart recovery are published — delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H