The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control. | |
| Title | SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-10T06:00:10.076Z
Reserved: 2026-09-21T09:02:42.996Z
Link: CVE-2026-94256
No data.
Status : Received
Published: 2026-10-10T06:16:44.590
Modified: 2026-10-10T06:16:44.590
Link: CVE-2026-94256
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.