What is CVE-2026-15206?
The SMS Alert WordPress plugin before version 3.9.8 fails to bind the 'mobile verified' session flag to the originally verified phone number. This allows an attacker to verify an OTP sent to their own phone and then supply a different phone number during login to access that account. Updating to version 3.9.8 or later is strongly recommended.
Azərbaycanca: SMS Alert WordPress plugin-in 3.9.8-dən əvvəlki versiyalarında "mobile verified" sessiya bayrağı təsdiqlənmiş telefon nömrəsinə bağlanmır. Bu zəiflik təcavüzkarın öz telefon nömrəsini təsdiqlədikdən sonra təqdim etdiyi fərqli nömrə ilə hesaba daxil olmasına şərait yaradır. Plugin-i dərhal 3.9.8 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the SMS Alert plugin are affected by CVE-2026-15206?
This vulnerability affects all versions of the SMS Alert WordPress plugin before version 3.9.8.
What action can an attacker exploiting CVE-2026-15206 perform due to the 'mobile verified' session flag issue?
An attacker can verify an OTP sent to their own phone and then supply a different phone number during login to access the account associated with that different number.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.