CVE-2026-15014 (matched: wordpress)

  • Tuesday, 28th July, 2026
  • 10:04am

A security vulnerability has been identified in the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress. All versions of the plugin up to and including 3.9.7 are affected by a flaw that allows unauthenticated attackers to bypass login security and take over user accounts on sites running the plugin, including high-level administrator accounts.

The issue stems from a mistake in how the plugin handles one-time passcode (OTP) verifications sent to phone numbers. When a user enters a valid OTP, the plugin sets a simple flag to mark the verification as successful, but this flag is not linked to the specific phone number that completed the verification. An attacker can first verify an OTP for a phone number they control, then resubmit a registration request using a victim's known or guessable registered phone number (such as an administrator's) to trigger a valid login for the victim's account.

Successful exploitation lets attackers gain full access to any existing WordPress user account on the affected site whose registered phone number is known or guessable, including administrator accounts that have full control over the site, its store settings, and customer data.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15014

« Back