PatchSiren

SMS Alert CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review SMS Alert CVE published 2026-10-08

CVE-2026-94258

The SMS Alert WordPress plugin before 4.0.1 allows an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site. The vulnerability is specific to multisite installations and in [truncated]