{"id":"CVE-2026-15206","title":"The SMS Alert  WordPress plugin before 3.9.8 does not bind its \"mobile verified\" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fre…","summary":"The SMS Alert  WordPress plugin before 3.9.8 does not bind its \"mobile verified\" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fre…","severity":"none","published":"2026-08-02","updated":"2026-08-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15206","references":[{"url":"https://wpscan.com/vulnerability/d0bb4c41-392a-4209-9e44-93dbf3898417/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-02T13:18:29.033Z","epss":0.00262,"epssPercentile":0.1833,"slug":"CVE-2026-15206","body":"## Overview\n\nThe SMS Alert  WordPress plugin before 3.9.8 does not bind its \"mobile verified\" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}