WORDPRESS · JULY 2026 · EARLY WARNING

SMS Alert WooCommerce Plugin Vulnerable to Account Takeover

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-15014Severity: CRITICAL

The SMS Alert – SMS & OTP for WooCommerce plugin for WordPress is under investigation for a critical vulnerability that could allow Authentication Bypass leading to Account Takeover via the billing_phone parameter in versions up to 3.9.7.

What happened

An early warning has been issued regarding a critical vulnerability in the SMS Alert – SMS & OTP for WooCommerce plugin for WordPress. The vulnerability, tracked as CVE-2026-15014, reportedly affects all versions up to and including 3.9.7. It appears to allow Authentication Bypass leading to Account Takeover via the billing_phone parameter. This is due to the processRegistration() function using a phone-unbound session flag as the sole gate before issuing an authentication cookie. The flag is set to true after any successful OTP validation without being bound to the specific phone number that was verified, making it possible for unauthenticated attackers to exploit this.

To assess your exposure, check if you are running a version of the SMS Alert – SMS & OTP for WooCommerce plugin up to 3.9.7. If so, it is recommended to upgrade to a version beyond 3.9.7 as soon as possible. Additionally, review any suspicious logins or activities in your affected environments. For more detailed information, consult the primary sources linked in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If sms-alert-woocommerce is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats