Information Disclosure Vulnerability in SMS Alert WordPress Plugin
CVE-2026-94258

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
8 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-94258?

The SMS Alert plugin for WordPress has a significant information disclosure flaw found in versions prior to 4.0.1. This vulnerability enables an unauthorized administrator within a multisite network to access and reveal the billing phone numbers of users across different sites. The issue arises from inadequate checks that should verify the acting administrator's permissions to manage users, leading to potential privacy breaches. Administrators can exploit this situation if they have suitable gateway credentials stored on their site, making it crucial for users operating multisite installations to upgrade to at least version 4.0.1 to protect sensitive information.

Affected Version(s)

SMS Alert 3.6.4 < 4.0.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muni Nitish Kumar Yaddala
WPScan
.