PatchSiren cyber security CVE debrief
CVE-2026-94257 SMS Alert CVE debrief
The SMS Alert WordPress plugin before 4.0.1 has a critical unauthenticated privilege escalation vulnerability via arbitrary password reset. This issue allows attackers to set a new password on an arbitrary account, including administrators, by verifying a one-time code sent to a phone number they control. The vulnerability exists in versions 3.9.6 to 4.0.0, and defenders should assess exposure and prioritize verification and remediation. The CVE record and source item provide details on the vulnerability, but additional context or verification may be available from other sources.
- Vendor
- SMS Alert
- Product
- SMS Alert
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the SMS Alert plugin, particularly those using versions 3.9.6 to 4.0.0, should assess exposure and prioritize verification and remediation.
Why it matters
CVE-2026-94257 is a critical vulnerability in the SMS Alert WordPress plugin that allows unauthenticated attackers to escalate privileges by resetting passwords on arbitrary accounts. Defenders should prioritize verifying exposure, applying compensating controls, and monitoring for suspicious activity.
- Defenders must verify exposure of SMS Alert versions 3.9.6 to 4.0.0 to prevent potential privilege escalation.
- Successful exploitation could allow attackers to gain administrative access to WordPress installations.
- Defenders should prioritize applying compensating controls to limit access to the SMS Alert plugin until a patch is verified.
- Verification of inventory and monitoring for suspicious activity related to password reset attempts are necessary.
Technical summary
The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset. This allows unauthenticated attackers to set a new password on an arbitrary account, including administrators, by verifying a one-time code sent to a phone number they control. The vulnerability exists in versions 3.9.6 to 4.0.0 and allows for privilege escalation. Defenders should prioritize verifying exposure and applying compensating controls.
Defensive priority
Defenders should prioritize verifying exposure of SMS Alert versions 3.9.6 to 4.0.0 and applying compensating controls until a patch is verified.
Recommended defensive actions
- Verify exposure of SMS Alert versions 3.9.6 to 4.0.0 in the environment
- Apply compensating controls to limit access to the SMS Alert plugin
- Monitor for suspicious activity related to password reset attempts
- Consider upgrading to SMS Alert version 4.0.1 or later when available
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability. However, the NVD entry and other sources may offer additional context or verification of the issue. Defenders should verify exposure of SMS Alert versions 3.9.6 to 4.0.0 and apply compensating controls until a patch is verified. The vulnerability allows unauthenticated attackers to escalate privileges by resetting passwords on arbitrary accounts. The source item and CVE record provide source-provided CVE metadata and details on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94257 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94257
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94257 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94257
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94257.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/4c32fa5b-4677-4f62-8856-fbe9c601fc36/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.