Unauthorized Password Reset Vulnerability in SMS Alert WordPress Plugin
CVE-2026-94257
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-94257?
The SMS Alert WordPress plugin has a security flaw where it fails to correctly bind the password reset process to the verified phone number associated with user accounts. This allows attackers, without authentication, to change passwords for any user, including administrators, by leveraging their control over a one-time code sent to their own phone number. This vulnerability exposes sites to significant security risks, potentially enabling unauthorized access to sensitive accounts.
Affected Version(s)
SMS Alert 3.9.6 < 4.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.