Authentication Bypass Vulnerability in SMS Alert Plugin for WooCommerce
⚠️ CVE-Referenzen:
CVE-2026-15014
WordPress - Sms Alert – Sms & Otp For WooCommerce, Order Notifications & Abandoned Cart Recovery - CRITICAL - CVE-2026-15014.
The SMS Alert – SMS & OTP for WooCommerce plugin is susceptible to an authentication bypass vulnerability that could lead to account takeover. This issue arises from a flaw in the `processRegistration()` function, which relies on a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag to authenticate users. An attacker can exploit this vulnerability by successfully validating an OTP for their own phone number and then resubmitting a registration request with the victim's `billing_phone` number. This process allows the attacker to gain authentication cookies tied to any account, including those of administrators, without the legitimate user's consent or knowledge.
Quelle: securityvulnerability.io