{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/sms-alert/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15014"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SMS Alert – SMS \u0026 OTP for WooCommerce, Order Notifications \u0026 Abandoned Cart Recovery plugin (\u003c 3.9.7)","WordPress"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","account-takeover","web-application","cve"],"_cs_type":"advisory","_cs_vendors":["SMS Alert","WordPress"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability, identified as CVE-2026-15014, affects all versions up to and including 3.9.7 of the \u0026quot;SMS Alert - SMS \u0026amp; OTP for WooCommerce, Order Notifications \u0026amp; Abandoned Cart Recovery\u0026quot; plugin for WordPress. This flaw enables unauthenticated attackers to perform account takeover. The vulnerability stems from the \u003ccode\u003eprocessRegistration()\u003c/code\u003e function's improper handling of the \u003ccode\u003e$_SESSION['sa_mobile_verified']\u003c/code\u003e boolean flag, which is set to \u003ccode\u003etrue\u003c/code\u003e after any successful One-Time Password (OTP) validation but is not bound to a specific phone number. This allows an attacker to complete OTP verification using a phone number they control, then subsequently submit a crafted registration request using a victim's known or guessable \u003ccode\u003ebilling_phone\u003c/code\u003e value. This manipulation bypasses proper authentication, leading to the issuance of an authentication cookie for the victim's account and granting the attacker full control, including administrative access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker initiates the OTP verification process within the vulnerable WordPress plugin using a phone number under their control.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully completes the OTP verification using their own phone number.\u003c/li\u003e\n\u003cli\u003eThe plugin's \u003ccode\u003eprocessRegistration()\u003c/code\u003e function sets the \u003ccode\u003e$_SESSION['sa_mobile_verified']\u003c/code\u003e flag to \u003ccode\u003etrue\u003c/code\u003e, indicating a successful OTP validation, but critically, this flag remains unbound to the specific phone number used for verification.\u003c/li\u003e\n\u003cli\u003eThe attacker then constructs and sends a specially crafted HTTP POST request targeting the plugin's registration endpoint, which utilizes the \u003ccode\u003eprocessRegistration()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eIn this request, the attacker includes the \u003ccode\u003ebilling_phone\u003c/code\u003e parameter, supplying the known or guessable phone number of a legitimate WordPress user account (the victim).\u003c/li\u003e\n\u003cli\u003eDue to the previously set, phone-unbound \u003ccode\u003e$_SESSION['sa_mobile_verified']\u003c/code\u003e flag, the \u003ccode\u003eprocessRegistration()\u003c/code\u003e function proceeds as if the victim's phone number has been legitimately verified.\u003c/li\u003e\n\u003cli\u003eThe function then calls \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e, resolving the victim's account based on the provided \u003ccode\u003ebilling_phone\u003c/code\u003e and issuing an authentication cookie for that account to the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the stolen authentication cookie to gain full access and control over the victim's WordPress account, potentially including administrator privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15014 results in complete account takeover for any WordPress user whose registered phone number is known or can be guessed by the attacker. This includes high-privilege accounts such as administrators, leading to severe consequences including website defacement, data theft, arbitrary code execution (via plugin/theme editing), or further compromise of the web server. The CVSS v3.1 Base Score of 9.8 reflects the critical nature of this vulnerability, indicating easy exploitability and high impact on confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the \u0026quot;SMS Alert - SMS \u0026amp; OTP for WooCommerce, Order Notifications \u0026amp; Abandoned Cart Recovery\u0026quot; plugin to a version patched against CVE-2026-15014 to prevent authentication bypass.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-15014 Exploitation Attempt (WordPress SMS Alert Plugin)\u0026quot; to your SIEM to identify suspicious interactions with the vulnerable \u003ccode\u003eprocessRegistration()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eRegularly review web server access logs for repeated \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e involving plugin-specific actions and the \u003ccode\u003ebilling_phone\u003c/code\u003e parameter, as identified in the detection rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T08:19:24Z","date_published":"2026-07-28T08:19:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-15014-wordpress-sms-alert-auth-bypass/","summary":"An authentication bypass vulnerability (CVE-2026-15014) in the 'SMS Alert - SMS \u0026 OTP for WooCommerce, Order Notifications \u0026 Abandoned Cart Recovery' WordPress plugin allows unauthenticated attackers to achieve account takeover by exploiting a flaw in the `processRegistration()` function's OTP verification, enabling authentication as any existing WordPress user with a known phone number.","title":"Authentication Bypass in WordPress SMS Alert Plugin Leads to Account Takeover (CVE-2026-15014)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-15014-wordpress-sms-alert-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - SMS Alert","version":"https://jsonfeed.org/version/1.1"}