CVE-2026-62106
largePrivilege Escalation in WordPress SMS Alert Order Notifications plugin <= 3.9.9
CVE-2026-62106 is an incorrect privilege-assignment flaw (CWE-266) in the WordPress plugin SMS Alert Order Notifications, affecting every version up to and including 3.9.9. A user holding only a subscriber-level account can send a crafted authenticated request to the plugin's inadequately protected routine and have their account's role or capabilities elevated, typically to administrator. That grants effectively full control of the affected site (reading or modifying data, changing settings, installing or editing plugins), consistent with the 8.8 high CVSS score with high confidentiality, integrity and availability impacts. Affected sites are WordPress installations, generally WooCommerce stores using the plugin for SMS order notifications, particularly where an attacker can obtain or self-register a subscriber account. As of this report there is no public proof-of-concept, the issue is not in CISA KEV, and no exploitation in the wild is known; remediation is to update to a release newer than 3.9.9.
What to do: Update SMS Alert Order Notifications to the latest available release (anything newer than 3.9.9). Until patched, reduce exposure by disabling or restricting open subscriber registration and review low-privileged accounts and any recent role changes for signs of tampering. Because exploitation requires a subscriber-level account, sites that do not allow self-registration face materially lower risk.
| Cozy Vision Technologies SMS Alert Order Notifications (WordPress plugin) | <= 3.9.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.