Sceawere
Vulnerability Detail
CVE-2026-95594UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Privilege Escalation in SMS Alert Order Notifications
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 16h ago
- Vendor
- Cozy Vision Technologies Pvt. Ltd.
- Product
- SMS Alert Order Notifications
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-06T09:17:57.577Z",
"pubdate": "2026-10-06T09:17:57.577Z",
"executiveSummary": "The SMS Alert Order Notifications plugin for WordPress, specifically in versions 4.0.0 and below, contains a critical security flaw involving unauthenticated privilege escalation.\nThis vulnerability allows an unauthenticated remote attacker to perform unauthorized administrative actions or escalate their privileges within the target application.\nThe vulnerability resides in the way the plugin handles incoming requests, failing to enforce necessary authorization checks before executing sensitive operations.\nSuccessful exploitation poses a severe risk to the integrity and confidentiality of the WordPress installation, as it enables malicious actors to bypass standard authentication mechanisms.\nThis allows attackers to gain unauthorized access to administrative functions, potentially leading to full site compromise, sensitive data exfiltration, and the execution of arbitrary code if additional plugins or themes are leveraged post-compromise.\nNo specific user interaction is required for a successful exploit, as the attack can be executed remotely via crafted HTTP requests.\nThe vulnerability highlights a significant failure in access control validation for plugin-specific endpoints, necessitating immediate administrative intervention.",
"technicalDetails": "The core of the vulnerability lies in the improper implementation of access control checks within the SMS Alert Order Notifications plugin. Specifically, the plugin endpoints responsible for administrative notification settings or order processing routines fail to verify the session or authentication status of the requester.\nBy neglecting to invoke standard WordPress authentication hooks—such as current_user_can() or is_user_logged_in()—the plugin treats requests from unauthenticated users as if they were originated by an authorized administrator.\nThe attack flow initiates when an attacker identifies the specific public-facing endpoint used by the plugin to process notification alerts. Because the application logic does not validate the requester's identity or authorization level, an attacker can send a crafted HTTP POST or GET request directly to the vulnerable function.\nThe payload typically includes parameters that manipulate plugin settings, such as modifying notification recipients, enabling administrative features, or triggering administrative functions that should be restricted to authenticated administrators.\nUpon receiving the malicious request, the backend executes the logic associated with the endpoint, effectively bypassing the application’s security perimeter. This allows the attacker to modify site configurations that may result in further vulnerability exposure or complete unauthorized administrative control.\nThe vulnerability is present in versions 4.0.0 and below, affecting all standard installations where the plugin is active and accessible via the web server. The lack of nonce verification or capability checks exacerbates the risk, as it allows for trivial exploitation of these exposed functions.\nPost-exploitation impact is severe, as privilege escalation at this level often allows an attacker to inject malicious administrative users, modify global site settings, or exfiltrate sensitive order information stored in the WordPress database. Furthermore, if the plugin has high-level permissions or interacts with sensitive API endpoints, the attacker may pivot to wider exploitation of the WordPress environment, leading to persistent backdooring of the installation or further compromise of the underlying hosting infrastructure."
}