---
id: CVE-2026-94256
title: >-
  The SMS Alert  WordPress plugin before 4.0.1 does not verify that the account
  being logged in is the one the verified one-time code belongs to, allowing
  unauthenticated attackers to sign in as any user with a stored phone number,
  includi…
summary: >-
  The SMS Alert  WordPress plugin before 4.0.1 does not verify that the account
  being logged in is the one the verified one-time code belongs to, allowing
  unauthenticated attackers to sign in as any user with a stored phone number,
  includi…
severity: none
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T06:16:44.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94256'
references:
  - url: 'https://wpscan.com/vulnerability/38b4e7f9-d73e-4c4d-bb9c-4c2dd1f4d7d9/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-10T06:24:42.873Z'
---

## Overview

The SMS Alert  WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
