CVE-2026-11387

CRITICAL

SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-11387. PoCs published by HermesNA-1, 1beelze.

AI-analyzed exploit summary This repository contains an auto-generated placeholder module for CVE-2026-11387, a privilege escalation vulnerability in the 'SMS Alert – SMS & OTP for WooCommerce' WordPress plugin. The code includes references to vulnerable code paths but lacks actual exploit implementation, serving only as a template.

Description

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. This is only vulnerable on sites with OTP verification for password resets enabled, and where the administrator (or other user) has set a phone number for OTP verification.

Exploits (2)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-11387_the_sms_alert.py

This repository contains an auto-generated placeholder module for CVE-2026-11387, a privilege escalation vulnerability in the 'SMS Alert – SMS & OTP for WooCommerce' WordPress plugin. The code includes references to vulnerable code paths but lacks actual exploit implementation, serving only as a template.

Classification
Stub 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: SMS Alert – SMS & OTP for WooCommerce plugin for WordPress (versions up to and including 3.9.5)
No auth needed
Prerequisites: Target must have the vulnerable WordPress plugin installed and accessible via HTTP/HTTPS
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →
github WORKING POC 1 stars
by 1beelze · pythonpoc
https://github.com/1beelze/CVE-2026-11387

This repository contains a functional Python exploit for CVE-2026-11387, an unauthenticated privilege escalation vulnerability in the SMS Alert WordPress plugin (≤3.9.5). The exploit bypasses OTP verification by leveraging a race condition in session seeding, allowing arbitrary password resets for any user with a registered billing phone number.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: SMS Alert – OTP Verification for WooCommerce (WordPress plugin) ≤ 3.9.5
No auth needed
Prerequisites: Target user must have a billing phone number registered in WooCommerce · WordPress site must have the vulnerable plugin version (≤3.9.5) installed
mistral-large-3 · analyzed Jul 03, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0038
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
cozyvision1/SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery < 3.9.5
Published Jul 01, 2026
Tracked Since Jul 01, 2026