Authentication Bypass Vulnerability in SMS Alert Plugin for WooCommerce
CVE-2026-15014
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15014?
The SMS Alert β SMS & OTP for WooCommerce plugin is susceptible to an authentication bypass vulnerability that could lead to account takeover. This issue arises from a flaw in the processRegistration() function, which relies on a phone-unbound $_SESSION['sa_mobile_verified'] boolean flag to authenticate users. An attacker can exploit this vulnerability by successfully validating an OTP for their own phone number and then resubmitting a registration request with the victim's billing_phone number. This process allows the attacker to gain authentication cookies tied to any account, including those of administrators, without the legitimate user's consent or knowledge.
Affected Version(s)
SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 0 <= 3.9.7