PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94257 SMS Alert CVE debrief

The SMS Alert WordPress plugin before 4.0.1 has a critical unauthenticated privilege escalation vulnerability via arbitrary password reset. This issue allows attackers to set a new password on an arbitrary account, including administrators, by verifying a one-time code sent to a phone number they control. The vulnerability exists in versions 3.9.6 to 4.0.0, and defenders should assess exposure and prioritize verification and remediation. The CVE record and source item provide details on the vulnerability, but additional context or verification may be available from other sources.

Vendor
SMS Alert
Product
SMS Alert
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the SMS Alert plugin, particularly those using versions 3.9.6 to 4.0.0, should assess exposure and prioritize verification and remediation.

Why it matters

CVE-2026-94257 is a critical vulnerability in the SMS Alert WordPress plugin that allows unauthenticated attackers to escalate privileges by resetting passwords on arbitrary accounts. Defenders should prioritize verifying exposure, applying compensating controls, and monitoring for suspicious activity.

  • Defenders must verify exposure of SMS Alert versions 3.9.6 to 4.0.0 to prevent potential privilege escalation.
  • Successful exploitation could allow attackers to gain administrative access to WordPress installations.
  • Defenders should prioritize applying compensating controls to limit access to the SMS Alert plugin until a patch is verified.
  • Verification of inventory and monitoring for suspicious activity related to password reset attempts are necessary.

Technical summary

The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset. This allows unauthenticated attackers to set a new password on an arbitrary account, including administrators, by verifying a one-time code sent to a phone number they control. The vulnerability exists in versions 3.9.6 to 4.0.0 and allows for privilege escalation. Defenders should prioritize verifying exposure and applying compensating controls.

Defensive priority

Defenders should prioritize verifying exposure of SMS Alert versions 3.9.6 to 4.0.0 and applying compensating controls until a patch is verified.

Recommended defensive actions

  • Verify exposure of SMS Alert versions 3.9.6 to 4.0.0 in the environment
  • Apply compensating controls to limit access to the SMS Alert plugin
  • Monitor for suspicious activity related to password reset attempts
  • Consider upgrading to SMS Alert version 4.0.1 or later when available
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability. However, the NVD entry and other sources may offer additional context or verification of the issue. Defenders should verify exposure of SMS Alert versions 3.9.6 to 4.0.0 and apply compensating controls until a patch is verified. The vulnerability allows unauthenticated attackers to escalate privileges by resetting passwords on arbitrary accounts. The source item and CVE record provide source-provided CVE metadata and details on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94257 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94257

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94257 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94257

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.