๐Ÿ” CVE Alert

CVE-2026-15206

UNKNOWN 0.0

SMS Alert Order Notifications โ€“ WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.

Vendor unknown
Product sms alert
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown sms alert

Be the first to know when new unknown vulnerabilities affecting unknown sms alert are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / SMS Alert
0 < 3.9.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d0bb4c41-392a-4209-9e44-93dbf3898417/

Credits

Sai Praneeth Koti WPScan