What is CVE-2026-15014?
An Authentication Bypass vulnerability in the SMS Alert plugin for WordPress allows Account Takeover via the `billing_phone` parameter in versions up to 3.9.7. The flaw exists in the `processRegistration()` function, enabling unauthorized access. Immediate plugin update is required.
Azərbaycanca: WordPress üçün SMS Alert plaginində `billing_phone` parametri vasitəsilə autentifikasiyadan yan keçmə (Authentication Bypass) zəifliyi aşkar edilib. Bu boşluq 3.9.7 və daha əvvəlki versiyalara təsir edir və təcavüzkara `processRegistration()` funksiyası üzərindən hesabı ələ keçirməyə (Account Takeover) imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which plugin does CVE-2026-15014 affect?
CVE-2026-15014 affects the SMS Alert plugin for WordPress.
What can an attacker achieve by exploiting CVE-2026-15014?
An attacker can perform Account Takeover by exploiting the `billing_phone` parameter via the `processRegistration()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.