Privilege Escalation in SMS Alert Plugin for WooCommerce
CVE-2026-11387

9.8CRITICAL

Key Information:

Badges

πŸ“ˆ Score: 938πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-11387?

CVE-2026-11387 is a critical vulnerability found in the SMS Alert – SMS & OTP plugin for WooCommerce, a popular tool used within the WordPress ecosystem for managing order notifications and enhancing customer engagement through SMS alerts. This vulnerability allows unauthorized users to escalate privileges through account takeover by exploiting the plugin's inadequate user identity validation processes. Specifically, attackers can manipulate the password reset functionality associated with user accounts, including those of administrators, if they have set up SMS-based one-time password (OTP) verification. This flaw results in the ability for unauthenticated attackers to change the email address linked to any user account, effectively enabling them to reset the password and gain full access to that account. The vulnerability is present in all versions of the plugin up to 3.9.5 and poses a significant risk to organizations relying on this plugin for their e-commerce operations.

Potential impact of CVE-2026-11387

  1. Account Takeover: The primary risk associated with CVE-2026-11387 is the unauthorized access to user accounts, including those of administrative users. Attackers can exploit this vulnerability to take over accounts, potentially leading to the exposure of sensitive customer information and control over backend systems.

  2. Data Breach Risks: By gaining administrative access, attackers could compromise sensitive data, leading to significant data breaches. This not only jeopardizes customer trust but can also result in legal implications and financial penalties due to violations of data protection regulations.

  3. Operational Disruption: The ability for unauthorized users to change account settings and gain access to critical business functionalities can result in operational disruptions. Organizations may face significant downtime as they work to remediate the effects of the breach, leading to lost revenue and damage to reputation.

Affected Version(s)

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 0 <= 3.9.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chloe Chamberland
PRISM
.