Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94258— SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions

Quick assessment

Affected
Unknown SMS Alert
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 SMS Alert WordPress 插件 4.0.1 之前的版本中,系统在返回已存储的计费电话号码之前,未验证当前管理员用户是否有权管理所选择的用户。这一缺陷导致在多站点网络中,拥有其中一个站点管理员权限的用户可以泄露属于该网络中其他站点用户的电话号码。 该漏洞仅影响多站点网络环境,并且要求 SMS Alert WordPress 插件 4.0.1 之前版本的网关凭证存储在具有管理员权限的用户自身站点上。

AI Predicted 5.6 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94258

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions
Source: CVE Program / CVE List V5
Vulnerability Description
The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown SMS Alert 3.6.4 ~ 4.0.1 -

II. Public POCs for CVE-2026-94258

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94258

请登录查看更多情报信息。

Other References for CVE-2026-94258 (1)

Same Patch Batch · Unknown · 2026-10-08 · 20 CVEs total

CVE-2026-105196 LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API
CVE-2026-103309 GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage
CVE-2026-103646 Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' Pa
CVE-2026-104646 Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortc
CVE-2026-104645 Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Im
CVE-2026-103692 Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Func
CVE-2026-105195 Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
CVE-2026-105197 LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR
CVE-2026-105198 LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR
CVE-2026-105194 Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Dow
CVE-2026-94245 Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Arbitrary Wallet Balance Theft
CVE-2026-105193 Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification
CVE-2026-86826 BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory
CVE-2026-86827 BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php
CVE-2026-86828 BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback
CVE-2026-105260 Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF
CVE-2026-94246 Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Reques
CVE-2026-94244 Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclosu
CVE-2026-94275 Track Orders for WooCommerce < 1.2.7 - Unauthenticated PII Disclosure via 'email' Paramete

IV. Related Vulnerabilities

V. Comments for CVE-2026-94258

No comments yet


Leave a comment