Sceawere
Vulnerability Detail
CVE-2026-94258UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SMS Alert Multisite Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- SMS Alert
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-10-08T06:16:47.143Z",
"pubdate": "2026-10-08T06:16:47.143Z",
"executiveSummary": "The SMS Alert WordPress plugin before version 4.0.1 suffers from an authorization bypass vulnerability that leads to unauthorized information disclosure in WordPress multisite installations. An administrator of a single site within a multisite network can exploit this flaw to retrieve and disclose the stored billing phone numbers of users belonging to other sites on the same network. This security gap exists because the plugin fails to verify whether the requesting administrator possesses the authorized permissions to manage the specific users whose data is being requested.\nTo successfully exploit this vulnerability, two specific conditions must be met: the WordPress installation must be configured as a multisite network, and the SMS Alert plugin's gateway credentials must be configured and stored on the acting administrator's own sub-site. If these prerequisites are satisfied, any site administrator on the network can bypass standard multi-tenant boundaries. This poses a significant confidentiality risk, potentially exposing sensitive user data across the entire multisite infrastructure, which can result in privacy violations and unauthorized data harvesting.",
"technicalDetails": "The root cause of this vulnerability is the absence of proper object-level access control within the SMS Alert WordPress plugin prior to version 4.0.1. In a WordPress multisite environment, user records are stored globally in the database but are logically segmented across different sub-sites. Administrators of individual sub-sites are restricted to managing users associated with their specific site. However, the plugin's data retrieval endpoints do not properly enforce these boundaries when querying billing phone numbers.\nWhen an administrative user requests billing phone numbers, the vulnerable plugin checks if the requester has administrative capabilities on their active sub-site and verifies that the SMS Alert gateway credentials are saved locally. It does not, however, perform a secondary validation step to confirm that the requested target user IDs belong to the same sub-site or that the requesting administrator has explicit authority over those specific user objects. This design flaw allows for cross-tenant data access.\nAn attack flow typically unfolds as follows: First, an attacker with administrator privileges on 'Sub-Site A' ensures that the SMS Alert gateway credentials are saved on 'Sub-Site A'. Next, the attacker identifies target user IDs belonging to 'Sub-Site B'. The attacker then issues an application request (such as an administrative AJAX action) querying the billing phone numbers for those target user IDs. Because the backend code lacks validation to map the target users to the requester's authorized scope, the plugin queries the global user meta database and returns the sensitive billing phone numbers associated with the target IDs back to the attacker on 'Sub-Site A'.\nThe vulnerability essentially breaks the logical isolation required in multi-tenant environments. By leveraging this flaw, a malicious or compromised sub-site administrator can systematically enumerate user IDs across the entire network and harvest their billing phone numbers, undermining the security posture of the entire WordPress multisite network. This can be executed via crafted administrative requests, allowing automated scripts to scrape user information in bulk without triggering standard WordPress security alerts."
}