{"id":"CVE-2026-94256","title":"The SMS Alert  WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, includi…","summary":"The SMS Alert  WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, includi…","severity":"none","published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T06:16:44.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94256","references":[{"url":"https://wpscan.com/vulnerability/38b4e7f9-d73e-4c4d-bb9c-4c2dd1f4d7d9/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T06:24:42.873Z","slug":"CVE-2026-94256","body":"## Overview\n\nThe SMS Alert  WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}