PatchSiren cyber security CVE debrief
CVE-2026-94258 SMS Alert CVE debrief
The SMS Alert WordPress plugin before 4.0.1 allows an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site. The vulnerability is specific to multisite installations and involves inadequate checks for administrator privileges when managing user data, potentially leading to unauthorized disclosure of sensitive information.
- Vendor
- SMS Alert
- Product
- SMS Alert WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Administrators of multisite WordPress installations using SMS Alert plugin versions 3.6.4 to 4.0.0 should assess exposure and verify administrator access controls. This includes reviewing user data management practices, ensuring proper segregation of duties, and restricting access to sensitive user information. Additionally, security teams and vulnerability management teams should prioritize patching or mitigating this vulnerability to prevent potential
Why it matters
CVE-2026-94258 allows administrators to disclose user phone numbers in multisite WordPress installations using SMS Alert plugin versions 3.6.4 to 4.0.0. Assess exposure, verify administrator access controls, and restrict access to sensitive user data.
- Potential unauthorized disclosure of user phone numbers
- Possible misuse of user data by administrators
- Required verification of administrator access controls
- Need for restricted access to sensitive user data
Technical summary
The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This vulnerability arises from insufficient privilege checks in the plugin's user management functionality, specifically when handling bulk user actions. The issue is confined to multisite installations and requires the plugin's gateway credentials to be stored on the administrator's site.
Defensive priority
Assess exposure in multisite WordPress installations using SMS Alert plugin versions 3.6.4 to 4.0.0; verify administrator access controls and user data management.
Recommended defensive actions
- Assess multisite WordPress installations for SMS Alert plugin versions 3.6.4 to 4.0.0
- Verify administrator access controls for user data management
- Restrict administrator access to sensitive user data
- Monitor for potential misuse of user data
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Official CVE Program record and NIST NVD detail page provide vulnerability metadata. WPScan source reference offers technical details on the plugin vulnerability. The CVE record was published on 2026-10-08T06:00:09.230Z and has not been modified since then. The vulnerability affects multisite installations of the SMS Alert WordPress plugin, versions 3.6.4 to 4.0.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94258 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94258
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94258 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94258
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94258.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/25af3225-3b4b-4882-9af8-ab24597f9be2/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.