Subscriber Privilege Escalation in SMS Alert Order Notifications by WordPress
CVE-2026-54803

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-54803?

The SMS Alert Order Notifications plugin for WordPress versions up to 3.9.4 is susceptible to a privilege escalation vulnerability. This issue enables unauthorized subscribers to gain enhanced access rights, potentially leading to unauthorized actions within the application. Taking prompt steps to apply patches or upgrades is crucial to safeguarding user data and maintaining the integrity of the WordPress site.

Affected Version(s)

SMS Alert Order Notifications <= 3.9.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou | Patchstack Bug Bounty Program
.