WordPress SMS Alert是WordPress基金会开源的一款短信提醒插件。 WordPress SMS Alert 3.9.7及之前版本存在授权问题漏洞,该漏洞源于对billing_phone参数处理不当,processRegistration()函数使用未绑定电话号码的$_SESSION['sa_mobile_verified']布尔标志作为签发身份验证cookie的唯一门控,导致未认证攻击者可完成对可控电话号码的OTP验证后重新提交注册请求,实现身份验证绕过并接管任何已知或可猜测电话号码
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | ≤ 3.9.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | 0 ~ 3.9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15671 | 4.9 MEDIUM | SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter |
| CVE-2026-15670 | 4.9 MEDIUM | SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter |
| CVE-2026-15673 | 4.4 MEDIUM | SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_pl |
No comments yet