CVE-2026-94257
SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset, allowing unauthenticated attackers to set a new password on an arbitrary account, including an administrator, by verifying a one-time code sent to a phone number they control.
| Vendor | unknown |
| Product | sms alert |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown sms alert
Be the first to know when new unknown vulnerabilities affecting unknown sms alert are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SMS Alert
3.9.6 < 4.0.1
References
Credits
Raphael P. Cigana WPScan