S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-11387 Scanner

CVE-2026-11387 Scanner - Privilege Escalation vulnerability in SMS Alert - SMS & OTP for WooCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-11387
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. This is only vulnerable on sites with OTP verification for password resets enabled, and where the administrator (or other user) has set a phone number for OTP verification.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recoveryby cozyvision1
0
Updated Aug 24, 2026View on NVD →
Detail

The SMS Alert - SMS & OTP for WooCommerce plugin is a widely used tool in the WordPress ecosystem, offering functionalities like SMS notifications, OTP for user verifications, and abandoned cart recovery. This plugin is particularly popular among eCommerce websites using WooCommerce for added security and customer communication. Webmasters and site administrators use it to streamline user interaction through OTP-based authentication for actions like password resets. Its integration with WooCommerce makes it an essential tool for businesses relying on WordPress for their online sales platforms. Many users rely on the timely SMS alerts for important updates related to their orders or account activities. However, being a popular add-on also exposes it to vulnerabilities when not properly maintained.

The Privilege Escalation vulnerability in this plugin arises when an unauthenticated attacker is able to change arbitrary user details without proper identity verification, leading to potential account takeovers. The risk exists when OTP verification is enabled for password resets and a phone number is associated with the account's OTP verification. This exploit allows attackers to change user emails and reset their passwords, thereby compromising user accounts, including those of administrators. Once inside, attackers have the potential to manipulate significant settings or data, escalating their unauthorized access. Such vulnerabilities are critical due to the potential for full administrative control being granted without prior authentication.

In technical detail, the vulnerability is exploited through the endpoint managing password reset functionalities. Attack vectors utilize crafted HTTP requests that manipulate parameters linked to password changes, bypassing typical authentication steps. The vulnerable parameter appears to be the user login credentials, which are inadequately verified before processing a password reset. Attackers send requests to specific endpoints, which do not thoroughly authenticate identities, allowing them to reset account passwords and access user data. These vectors demonstrate inadequate security practices at critical input points, facilitating unauthorized access. It is vital for systems relying on this plugin to customize or disable faulty functions until patches are applied.

If exploited, this vulnerability can allow attackers to perform full account takeovers by resetting passwords of admin accounts. This could lead to unauthorized management of web content, exposure of sensitive data, and use of high privileges to install additional malware or siphon data. Such access fundamentally violates user trust and can result in substantial data breaches. Website integrity is significantly compromised, enabling further exploitation or manipulation of website operations. It may also result in financial gain for attackers, misuse of administrative features, and complete disregard for user-set privacy controls.

REFERENCES

Solution Advice
  • Update the SMS Alert plugin to the latest version to patch the vulnerability.
  • Ensure OTP verification is accurately implemented and monitored for any misuse.
  • Regularly audit and monitor logs for unauthorized attempts or changes in user data.
  • Disable OTP verification temporarily if an immediate update is not possible.
  • Limit access to password reset features to prevent unauthorized usage.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.