CVE-2025-3876: SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to impersonate any account by supplying its username or email and elevate their privileges to that of an administrator.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3876?
CVE-2025-3876 is classified as a privilege escalation vulnerability due to insufficient user OTP validation.
How do I fix CVE-2025-3876?
To remediate CVE-2025-3876, update the WooCommerce SMS Alert Order Notifications plugin to version 3.8.2 or higher.
Who is affected by CVE-2025-3876?
All users of the WooCommerce SMS Alert Order Notifications plugin versions up to and including 3.8.1 are affected by CVE-2025-3876.
What does CVE-2025-3876 allow an attacker to do?
CVE-2025-3876 allows an authenticated attacker to escalate their privileges due to a lack of proper OTP validation.
When was CVE-2025-3876 disclosed?
CVE-2025-3876 was disclosed on October 17, 2025.