CVE-2024-13553

CRITICAL

SMS Alert Order Notifications < 3.7.9 - Unauthenticated Privilege Escalation via Host Header Spoofing

Title source: llm
STIX 2.1

Description

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticated attackers to spoof the Host header to make the OTP code "1234" and authenticate as any user, including administrators.

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 35.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-288
Status published
Products (2)
cozyvision/sms_alert_order_notifications < 3.8.0
cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery < 3.7.9
Published Apr 01, 2025
Tracked Since Feb 18, 2026