Junglewise Threat Intelligence

CVE-2026-59540: Cozy Vision SMS Alert Order Notifications unauthenticated privilege escalation

CVE-2026-59540 · Severity: critical · CVSS 9.8 · Published 2026-07-23

Technologies: Cozy Vision Technologies SMS Alert Order Notifications. Vendors: Cozy Vision Technologies.

Executive brief

A critical security flaw exists in the SMS Alert Order Notifications plugin for WordPress, which is used to send automated SMS updates to customers. An unauthorized attacker can exploit this vulnerability to gain administrative control over the website without needing a password. This could lead to a total site takeover, theft of customer data, or complete service disruption.

Technical details

The SMS Alert Order Notifications plugin for WordPress (versions 3.9.6 and below) contains a privilege escalation vulnerability due to incorrect privilege assignment (CWE-266). The flaw is located within the 'signup-with-mobile' completion step, where insufficient validation allows an unauthenticated remote attacker to escalate their privileges. Successful exploitation enables an attacker to gain full administrative control over the affected WordPress site. The issue is resolved in version 3.9.7.

Affected products

  • Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications <= 3.9.6

Timeline

  • 2026-07-06: disclosed: Reported by Taylsec
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: patched: Version 3.9.7 released to address the vulnerability

References

Related threats