Sceawere
Vulnerability Detail
CVE-2026-94256UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SMS Alert Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- SMS Alert
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-10T06:16:44.590Z",
"pubdate": "2026-10-10T06:16:44.590Z",
"executiveSummary": "The SMS Alert WordPress plugin prior to version 4.0.1 is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated remote attackers to gain unauthorized access to any WordPress account associated with a registered phone number.\nThe vulnerability stems from a logical flaw in the verification process, where the plugin fails to cryptographically or logically bind the validated one-time code to the specific user account requesting authentication.\nConsequently, an attacker who controls a phone number verified by the plugin can exploit this identity confusion to sign in as any other user, including administrative accounts, by triggering a verification challenge on their own device and presenting that valid code to the authentication endpoint for a target account.\nThis represents a critical security risk, as it permits full account takeover without valid credentials, leading to potential site compromise, data exfiltration, and administrative control. Exploitation is trivial and requires only the target user's phone number or username, which are often publicly accessible, and the ability to complete a standard SMS challenge.",
"technicalDetails": "The vulnerability resides within the authentication flow of the SMS Alert plugin, specifically where the server-side logic handles the validation of one-time passwords (OTP) sent via SMS. The root cause is a failure in session or user-binding validation: the plugin confirms the correctness of the code against a verification database but fails to verify that the target account identifier (UID or username) matches the identity for which the code was initially generated.\nThe attack flow proceeds as follows: First, the attacker identifies a target account, such as an administrator, that has a phone number associated with it in the WordPress database. Second, the attacker initiates a login request using their own phone number—a number that they have previously verified with the plugin to ensure they can successfully pass the system's SMS challenge. Third, upon receiving the OTP on their device, the attacker submits the valid code to the authentication endpoint. Because the server-side code only validates the OTP against the generic storage table for verified codes rather than enforcing a strict one-to-one relationship between the OTP, the phone number, and the targeted WordPress account, the authentication handler mistakenly approves the request.\nBecause the server does not enforce that the OTP issued for the attacker's phone number is restricted to their own account profile, the application logic incorrectly authenticates the user session as the target account. This is essentially an Insecure Direct Object Reference (IDOR) pattern applied to authentication state management. The vulnerable component is the OTP verification function, which performs insufficient authorization checks on the submission of the one-time code.\nThe impact is total account takeover. An attacker can transition from an unauthenticated state to an authenticated state with the privileges of any user on the platform. If the target is an administrator, the attacker gains full control over the WordPress environment, allowing for malicious plugin installation, execution of arbitrary PHP code, or the modification of site content. This bypass mechanism requires no prior knowledge of the target's password, effectively nullifying the protection provided by traditional password-based authentication when SMS two-factor authentication or login mechanisms are active via this plugin.\nThe vulnerability affects all versions of the SMS Alert plugin prior to 4.0.1. The attack is network-exploitable and requires zero privileges on the target system to initiate, as the login form is typically exposed to the public internet."
}