Junglewise Threat Intelligence

CVE-2026-62106: SMS Alert Order Notifications privilege escalation

CVE-2026-62106 · Severity: high · CVSS 8.8 · Published 2026-09-11

Technologies: Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications.

Executive brief

SMS Alert Order Notifications is a WordPress plugin that enables SMS notifications for WooCommerce orders. A privilege escalation vulnerability allows low-privilege user accounts (subscribers) to elevate themselves to administrator status, granting complete control over the affected WordPress site and its data.

Technical details

This is a privilege escalation vulnerability in the SMS Alert Order Notifications WordPress plugin affecting versions 3.9.9 and earlier. The vulnerability allows authenticated users with subscriber-level privileges to escalate their permissions to administrator status without proper authorization checks. The root cause is insufficient permission validation in the plugin's code. Attack precondition requires valid subscriber-level user credentials on the affected WordPress installation. Successful exploitation grants an attacker full administrative control over the WordPress site. The vulnerability has been patched in version 4.0.0.

Affected products

  • Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications <=3.9.9

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Version 4.0.0 patches the vulnerability

References