Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical1
High2
Medium2
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2026-07-01

CVE-2026-11387 - Sms Alert Plugin

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's…

PLUGIN Sms Alert

CVE-2026-11387

CRITICAL CVSS 9.8 2026-07-01
Threat Entry Updated 2025-05-21

CVE-2025-3878 - Sms Alert Plugin

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sms Alert

CVE-2025-3878

MEDIUM CVSS 6.4 2025-05-10
Threat Entry Updated 2025-05-21

CVE-2025-3876 - Sms Alert Plugin

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to impersonate any account by supplying its username or email and elevate their privileges to that of an administrator.

PLUGIN Sms Alert

CVE-2025-3876

HIGH CVSS 8.8 2025-05-10
Threat Entry Updated 2025-06-05

CVE-2024-11725 - Sms Alert Plugin

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. Please…

PLUGIN Sms Alert

CVE-2024-11725

HIGH CVSS 8.8 2025-01-07
Threat Entry Updated 2025-05-28

CVE-2024-10233 - Sms Alert Plugin

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Sms Alert

CVE-2024-10233

MEDIUM CVSS 6.4 2024-10-29
Scroll to top