CVE-2026-94256: Unknown Sms Alert

High severity, CVSS 8.1. EPSS: 0.1% chance of exploitation in the next 30 days.

The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.

Affected products

  • Unknown Sms Alert: from 4.0.0, before 4.0.1 (fixed in 4.0.1)

Published 2026-10-10. Last modified 2026-10-10.