Junglewise Threat Intelligence

CVE-2026-11387: CozyVision SMS Alert privilege escalation via account takeover

CVE-2026-11387 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Technologies: CozyVision SMS Alert. Vendors: CozyVision.

Executive brief

A security flaw in a popular WordPress plugin used for sending SMS notifications and one-time passwords (OTP) allows attackers to take over any user account, including administrators. By exploiting a weakness in how the plugin verifies identities during password resets, an attacker can change a user's email address and then reset their password to gain full control of the website. This could lead to total site compromise, data theft, and loss of service.

Technical details

The SMS Alert plugin for WordPress (versions up to 3.9.5) contains an improper authentication vulnerability (CWE-287) that allows for privilege escalation and account takeover. The root cause is a failure to properly validate a user's identity before allowing updates to account details, such as email addresses. An unauthenticated remote attacker can exploit this by changing an arbitrary user's email address and subsequently using the standard WordPress password reset flow to gain access. This vulnerability specifically affects sites where OTP verification for password resets is enabled and the target user (e.g., an administrator) has a phone number configured for OTP. A patch was introduced in version 3.9.6.

Affected products

  • CozyVision SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.5

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats