Unauthenticated Broken Authentication in SMS Alert Order Notifications Plugin by WordPress
CVE-2026-54802
7.5HIGH
What is CVE-2026-54802?
The SMS Alert Order Notifications plugin for WordPress, specifically versions up to 3.9.3, is susceptible to a serious vulnerability that allows unauthenticated users to exploit broken authentication mechanisms. This flaw could enable attackers to gain unauthorized access to user accounts and sensitive information, posing a significant security risk to websites that utilize this plugin. It is crucial for users and administrators to identify affected installations and take prompt action to mitigate potential threats, including updating to a secure version.
Affected Version(s)
SMS Alert Order Notifications <= 3.9.3