CVE-2024-13553
CRITICALSMS Alert Order Notifications < 3.7.9 - Unauthenticated Privilege Escalation via Host Header Spoofing
Title source: llmDescription
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticated attackers to spoof the Host header to make the OTP code "1234" and authenticate as any user, including administrators.
References (3)
Core 3
Core References
Scores
CVSS v3
9.8
EPSS
0.0044
EPSS Percentile
35.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
CWE-288
Status
published
Products (2)
cozyvision/sms_alert_order_notifications
< 3.8.0
cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
< 3.7.9
Published
Apr 01, 2025
Tracked Since
Feb 18, 2026