Subscriber Privilege Escalation in SMS Alert Order Notifications by WordPress
CVE-2026-62106
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-62106?
The SMS Alert Order Notifications plugin for WordPress, specifically in versions up to 3.9.9, contains a vulnerability that allows subscribers to escalate their privileges. This vulnerability could be exploited by a subscriber to gain unauthorized access to administrative functionalities, potentially compromising the integrity and security of the site.
Affected Version(s)
SMS Alert Order Notifications <= 3.9.9