Information Disclosure Vulnerability in SMS Alert WordPress Plugin
CVE-2026-94258
Key Information:
Badges
What is CVE-2026-94258?
The SMS Alert plugin for WordPress has a significant information disclosure flaw found in versions prior to 4.0.1. This vulnerability enables an unauthorized administrator within a multisite network to access and reveal the billing phone numbers of users across different sites. The issue arises from inadequate checks that should verify the acting administrator's permissions to manage users, leading to potential privacy breaches. Administrators can exploit this situation if they have suitable gateway credentials stored on their site, making it crucial for users operating multisite installations to upgrade to at least version 4.0.1 to protect sensitive information.
Affected Version(s)
SMS Alert 3.6.4 < 4.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.