Sceawere

Vulnerability Detail

CVE-2026-94257UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SMS Alert OTP Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
8h ago
Vendor
Unknown
Product
SMS Alert
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset, allowing unauthenticated attackers to set a new password on an arbitrary account, including an administrator, by verifying a one-time code sent to a phone number they control.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-10T06:16:44.717Z",
  "pubdate": "2026-10-10T06:16:44.717Z",
  "executiveSummary": "The SMS Alert WordPress plugin prior to version 4.0.1 contains a critical broken authentication vulnerability within its password reset mechanism. The flaw stems from improper validation of the relationship between an account's registered contact information and the session performing the password reset.\nSpecifically, the plugin fails to cryptographically bind or logically map the identity of the account being recovered to the phone number that successfully authenticated via One-Time Password (OTP). This allows unauthenticated remote attackers to bypass identity verification controls.\nAn attacker can exploit this by initiating a password reset request for any arbitrary account, including administrative accounts, and completing the OTP validation process using a phone number they control. The application incorrectly trusts the successful OTP validation as sufficient authorization to perform a password update on the target account, regardless of whether the verified phone number belongs to that account.\nThe risk implication is full account takeover, enabling unauthorized access to administrative privileges, data exfiltration, and potential complete site compromise. No pre-existing credentials or special privileges are required, making this a high-severity remote exploit.",
  "technicalDetails": "The root cause of this vulnerability is an insecure implementation of the password reset flow where the state management of the OTP validation process is decoupled from the user identity intended for recovery. In a secure implementation, the backend must verify that the phone number associated with the target account matches the phone number providing the valid OTP token.\nIn the affected SMS Alert versions, the application processes the password reset request through an unauthenticated endpoint. The attack flow proceeds as follows: First, the attacker identifies a target username or account identifier. Second, the attacker submits a password reset request for the target account via the plugin's interface. Third, instead of the system verifying the legitimate user's registered phone number, it prompts the user to provide a phone number for OTP verification. Fourth, the attacker provides a phone number they control and receives the OTP.\nUpon receiving the OTP, the attacker submits it to the validation endpoint. The plugin validates the OTP against the attacker-supplied phone number. Because the application logic fails to check if the verified phone number corresponds to the account being recovered, the server-side logic issues a success response for the identity verification phase. The application then proceeds to accept a new password from the attacker and updates the password hash for the target account in the wp_users table.\nThis vulnerability effectively turns the OTP mechanism into a generic authentication bypass vector. Since the plugin does not enforce a strict association between the user account ID and the verified contact method during the password update function call, the attacker can hijack any account on the platform without requiring prior knowledge of the existing password or access to the victim's legitimate registered credentials. This represents a complete failure of the authentication chain, exposing the WordPress installation to unauthorized administrative access. The vulnerability is exploitable over the network without requiring any prior authentication, making it a high-risk security flaw for any site utilizing the plugin's SMS-based reset functionality."
}
CVE-2026-94257: SMS Alert OTP Authentication Bypass (HIGH Severity, CVSS: 8.1) | Sceawere