Junglewise Threat Intelligence

CVE-2026-15014: Cozyvision SMS Alert authentication bypass in WooCommerce registration

CVE-2026-15014 · Severity: critical · CVSS 9.8 · Published 2026-07-28

Executive brief

A popular WordPress plugin used for WooCommerce order notifications and SMS-based login is vulnerable to a security flaw that allows attackers to take over user accounts. By exploiting a weakness in how the plugin verifies phone numbers during registration, an attacker can log in as any existing user, including administrators, if they know the user's registered phone number. This could lead to a total compromise of the website, theft of customer data, and unauthorized access to administrative functions.

Technical details

The vulnerability is classified as an authentication bypass (CWE-288) within the processRegistration() function. The root cause is the use of a session-based boolean flag, $_SESSION['sa_mobile_verified'], which is not cryptographically or logically bound to a specific phone number. An attacker can successfully validate an OTP for a phone number they control to set this flag to true, then resubmit the registration request using a victim's billing_phone number. Because the plugin only checks if the flag is true before calling wp_set_auth_cookie(), the attacker is granted a valid authentication cookie for the victim's account. This affects all versions up to and including 3.9.7.

Affected products

  • cozyvision1 SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery up to, and including, 3.9.7

Timeline

  • 2026-07-28: advisory: NVD published the CVE record based on Wordfence data.

References

Related threats