First published: Sat May 10 2025(Updated: )
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to impersonate any account by supplying its username or email and elevate their privileges to that of an administrator.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce SMS Alert Order Notifications | <=3.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3876 is classified as a privilege escalation vulnerability due to insufficient user OTP validation.
To remediate CVE-2025-3876, update the WooCommerce SMS Alert Order Notifications plugin to version 3.8.2 or higher.
All users of the WooCommerce SMS Alert Order Notifications plugin versions up to and including 3.8.1 are affected by CVE-2025-3876.
CVE-2025-3876 allows an authenticated attacker to escalate their privileges due to a lack of proper OTP validation.
CVE-2025-3876 was disclosed on October 17, 2025.