CVE-2026-94256 PUBLISHED

SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP

Assigner: WPScan
Reserved: 21.09.2026 Published: 10.10.2026 Updated: 10.10.2026

The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.

Product Status

Vendor Unknown
Product SMS Alert
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.1 (excl.)

Credits

  • Raphael P. Cigana finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE