Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Sat, 10 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control. | |
| Title | SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-10T06:00:10.076Z
Reserved: 2026-09-21T09:02:42.996Z
Link: CVE-2026-94256
No data.
Status : Received
Published: 2026-10-10T06:16:44.590
Modified: 2026-10-10T06:16:44.590
Link: CVE-2026-94256
No data.
OpenCVE Enrichment
Updated: 2026-10-10T07:30:14Z