CVE-2026-15206: SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15206?
The severity of CVE-2026-15206 is rated at 89, indicating a high risk of exploitation.
How do I fix CVE-2026-15206?
To fix CVE-2026-15206, update the SMS Alert WordPress plugin to version 3.9.8 or later.
What type of vulnerability is CVE-2026-15206?
CVE-2026-15206 is an unauthenticated account takeover vulnerability due to an issue with OTP verification.
Which software is affected by CVE-2026-15206?
CVE-2026-15206 affects the SMS Alert WordPress plugin versions prior to 3.9.8.
What does CVE-2026-15206 allow an attacker to do?
CVE-2026-15206 allows an attacker to take over user accounts by verifying a one-time password on their own phone.