SMS Alert WooCommerce Plugin Vulnerable to Account Takeover
The SMS Alert – SMS & OTP for WooCommerce plugin for WordPress is under investigation for a critical vulnerability that could allow Authentication Bypass leading to Account Takeover via the billing_phone parameter in versions up to 3.9.7.
What happened
An early warning has been issued regarding a critical vulnerability in the SMS Alert – SMS & OTP for WooCommerce plugin for WordPress. The vulnerability, tracked as CVE-2026-15014, reportedly affects all versions up to and including 3.9.7. It appears to allow Authentication Bypass leading to Account Takeover via the billing_phone parameter. This is due to the processRegistration() function using a phone-unbound session flag as the sole gate before issuing an authentication cookie. The flag is set to true after any successful OTP validation without being bound to the specific phone number that was verified, making it possible for unauthenticated attackers to exploit this.
To assess your exposure, check if you are running a version of the SMS Alert – SMS & OTP for WooCommerce plugin up to 3.9.7. If so, it is recommended to upgrade to a version beyond 3.9.7 as soon as possible. Additionally, review any suspicious logins or activities in your affected environments. For more detailed information, consult the primary sources linked in the threat data.
How 0Day mitigates this
sms-alert-woocommerce is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.