PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94258 SMS Alert CVE debrief

The SMS Alert WordPress plugin before 4.0.1 allows an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site. The vulnerability is specific to multisite installations and involves inadequate checks for administrator privileges when managing user data, potentially leading to unauthorized disclosure of sensitive information.

Vendor
SMS Alert
Product
SMS Alert WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Administrators of multisite WordPress installations using SMS Alert plugin versions 3.6.4 to 4.0.0 should assess exposure and verify administrator access controls. This includes reviewing user data management practices, ensuring proper segregation of duties, and restricting access to sensitive user information. Additionally, security teams and vulnerability management teams should prioritize patching or mitigating this vulnerability to prevent potential

Why it matters

CVE-2026-94258 allows administrators to disclose user phone numbers in multisite WordPress installations using SMS Alert plugin versions 3.6.4 to 4.0.0. Assess exposure, verify administrator access controls, and restrict access to sensitive user data.

  • Potential unauthorized disclosure of user phone numbers
  • Possible misuse of user data by administrators
  • Required verification of administrator access controls
  • Need for restricted access to sensitive user data

Technical summary

The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This vulnerability arises from insufficient privilege checks in the plugin's user management functionality, specifically when handling bulk user actions. The issue is confined to multisite installations and requires the plugin's gateway credentials to be stored on the administrator's site.

Defensive priority

Assess exposure in multisite WordPress installations using SMS Alert plugin versions 3.6.4 to 4.0.0; verify administrator access controls and user data management.

Recommended defensive actions

  • Assess multisite WordPress installations for SMS Alert plugin versions 3.6.4 to 4.0.0
  • Verify administrator access controls for user data management
  • Restrict administrator access to sensitive user data
  • Monitor for potential misuse of user data
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Official CVE Program record and NIST NVD detail page provide vulnerability metadata. WPScan source reference offers technical details on the plugin vulnerability. The CVE record was published on 2026-10-08T06:00:09.230Z and has not been modified since then. The vulnerability affects multisite installations of the SMS Alert WordPress plugin, versions 3.6.4 to 4.0.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94258 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94258

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94258 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94258

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.