Sceawere

Vulnerability Detail

CVE-2026-66424UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Privilege Escalation in SMS Alert

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
7h ago
Vendor
Cozy Vision Technologies Pvt. Ltd.
Product
SMS Alert Order Notifications
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-13T14:17:04.600Z",
  "pubdate": "2026-08-13T14:17:04.600Z",
  "executiveSummary": "An unauthenticated privilege escalation vulnerability has been identified in the SMS Alert Order Notifications plugin affecting versions 3.9.7 and below.\nThe vulnerability allows remote, unauthenticated threat actors to interact with poorly secured application logic or endpoints, leading to unauthorized elevation of privileges within the affected system.\nThe primary impact of this flaw includes the potential compromise of administrative controls, unauthorized data exposure, and full administrative takeover of the vulnerable WordPress installation depending on the exact execution context.\nThe risk implication is critical due to the lack of authentication requirements, allowing automated scanning and exploitation over the network without prior access credentials.\nAttackers require network connectivity to the target application and knowledge of the vulnerable endpoints to successfully execute the exploit payload.\nNo specialized user interaction is necessary for successful exploitation, increasing the likelihood of automated attacks in the wild.",
  "technicalDetails": "The vulnerability stems from improper access control enforcement and the lack of robust authentication checks within request handling routines of the SMS Alert Order Notifications plugin for versions <= 3.9.7.\nSpecifically, the affected component fails to properly validate whether an incoming HTTP request originates from an authenticated user with administrative privileges before processing sensitive state-changing operations or privilege-granting functions.\nAttackers can leverage this flaw by sending crafted HTTP requests directly to exposed AJAX actions, REST API endpoints, or direct script handlers associated with the plugin.\nBecause the underlying codebase lacks strict capability checks (such as current_user_can() validations) or nonce verification on the vulnerable functions, the application blindly processes the payload.\nThe attack flow proceeds as follows: First, the unauthenticated actor identifies the target endpoint exposed by the SMS Alert Order Notifications plugin. Second, the actor crafts a malicious request containing parameters designed to manipulate user roles, create administrative accounts, or invoke privileged backend functionality. Third, upon transmitting the request over the network, the vulnerable component processes the input without verifying session tokens or privilege levels. Finally, the application executes the requested operation, granting the attacker elevated privileges or unauthorized administrative access.\nThe attack vector is network-based and exploitable remotely without any prior authentication or local system privileges.\nPost-exploitation impact includes complete loss of confidentiality, integrity, and availability of the underlying web application, as the adversary can leverage the escalated privileges to execute arbitrary code, install malicious plugins, or modify system configurations."
}
CVE-2026-66424: Unauthenticated Privilege Escalation in SMS Alert (CRITICAL Severity, CVSS: 9.8) - Sceawere