Executive brief
The SMS Alert Order Notifications plugin for WordPress, which is used to send automated SMS updates for e-commerce orders, contains a critical security flaw. This vulnerability allows a low-privileged user, such as a standard subscriber, to gain administrative control over the website. An attacker could use this access to steal customer data, modify site content, or completely lock out the legitimate owners.
Technical details
The SMS Alert Order Notifications plugin for WordPress (versions 3.9.4 and below) is vulnerable to privilege escalation due to incorrect authorization checks (CWE-863). A remote attacker with 'Subscriber' level privileges can exploit this flaw to elevate their permissions to a higher level, potentially gaining full administrative access to the WordPress site. The vulnerability is characterized by a high CVSS score of 9.8, indicating it is easily automatable and requires no user interaction. A fix is available in version 3.9.5.
Affected products
- Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications <= 3.9.4
Timeline
- 2026-04-28: other: Reported by Peng Zhou
- 2026-06-16: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date
- 2026-06-17: patched: Version 3.9.5 released to address the vulnerability