ZeroHour

CVE-2026-62106

large

Privilege Escalation in WordPress SMS Alert Order Notifications plugin <= 3.9.9

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-62106 is an incorrect privilege-assignment flaw (CWE-266) in the WordPress plugin SMS Alert Order Notifications, affecting every version up to and including 3.9.9. A user holding only a subscriber-level account can send a crafted authenticated request to the plugin's inadequately protected routine and have their account's role or capabilities elevated, typically to administrator. That grants effectively full control of the affected site (reading or modifying data, changing settings, installing or editing plugins), consistent with the 8.8 high CVSS score with high confidentiality, integrity and availability impacts. Affected sites are WordPress installations, generally WooCommerce stores using the plugin for SMS order notifications, particularly where an attacker can obtain or self-register a subscriber account. As of this report there is no public proof-of-concept, the issue is not in CISA KEV, and no exploitation in the wild is known; remediation is to update to a release newer than 3.9.9.

What to do: Update SMS Alert Order Notifications to the latest available release (anything newer than 3.9.9). Until patched, reduce exposure by disabling or restricting open subscriber registration and review low-privileged accounts and any recent role changes for signs of tampering. Because exploitation requires a subscriber-level account, sites that do not allow self-registration face materially lower risk.

Affected
Cozy Vision Technologies SMS Alert Order Notifications (WordPress plugin)<= 3.9.9
Estimated exposure
large~10,000-30,000 WordPress sites (estimated; plugin directory reports roughly 10,000+ active installs) — WordPress.org directory statistics place this plugin at roughly 10,000+ active installations, and all releases through 3.9.9 are in scope, so essentially the entire install base is potentially affected - this is an estimate, not a figure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.