Privilege Escalation in SMS Alert Plugin for WooCommerce
CVE-2026-11387
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 July 2026
Badges
What is CVE-2026-11387?
CVE-2026-11387 is a critical vulnerability found in the SMS Alert β SMS & OTP plugin for WooCommerce, a popular tool used within the WordPress ecosystem for managing order notifications and enhancing customer engagement through SMS alerts. This vulnerability allows unauthorized users to escalate privileges through account takeover by exploiting the plugin's inadequate user identity validation processes. Specifically, attackers can manipulate the password reset functionality associated with user accounts, including those of administrators, if they have set up SMS-based one-time password (OTP) verification. This flaw results in the ability for unauthenticated attackers to change the email address linked to any user account, effectively enabling them to reset the password and gain full access to that account. The vulnerability is present in all versions of the plugin up to 3.9.5 and poses a significant risk to organizations relying on this plugin for their e-commerce operations.
Potential impact of CVE-2026-11387
-
Account Takeover: The primary risk associated with CVE-2026-11387 is the unauthorized access to user accounts, including those of administrative users. Attackers can exploit this vulnerability to take over accounts, potentially leading to the exposure of sensitive customer information and control over backend systems.
-
Data Breach Risks: By gaining administrative access, attackers could compromise sensitive data, leading to significant data breaches. This not only jeopardizes customer trust but can also result in legal implications and financial penalties due to violations of data protection regulations.
-
Operational Disruption: The ability for unauthorized users to change account settings and gain access to critical business functionalities can result in operational disruptions. Organizations may face significant downtime as they work to remediate the effects of the breach, leading to lost revenue and damage to reputation.
Affected Version(s)
SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved