Junglewise Threat Intelligence

CVE-2026-54802: Cozy Vision SMS Alert Order Notifications broken authentication

CVE-2026-54802 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Cozy Vision Technologies SMS Alert Order Notifications. Vendors: Cozy Vision Technologies.

Executive brief

A vulnerability exists in the SMS Alert Order Notifications plugin for WordPress, which is used to send automated SMS updates for e-commerce orders. An unauthenticated attacker can bypass security checks to access sensitive information or perform actions typically reserved for administrators. This could lead to unauthorized access to customer order data or full site takeover.

Technical details

The SMS Alert Order Notifications plugin for WordPress (versions <= 3.9.3) contains a broken authentication vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to perform actions that should be restricted to high-privileged users. According to the advisory, this could lead to the attacker gaining administrative access to the website. The vulnerability is reachable over the network without user interaction. A fix is available in version 3.9.4.

Affected products

  • Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications <= 3.9.3

Timeline

  • 2026-03-16: other: Vulnerability reported by Jakub Herman
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date
  • 2026-06-17: patched: Patch confirmed available in version 3.9.4

References

Related threats