Review
SMS Alert
CVE published 2026-10-08
CVE-2026-94258
The SMS Alert WordPress plugin before 4.0.1 allows an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site. The vulnerability is specific to multisite installations and in [truncated]