WordPress Plugin Vulnerabilities

SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP

Description

The plugin does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.
Exploitation requires the plugin's OTP login feature to be enabled, which is not the default.

Proof of Concept

Affects Plugins

Fixed in 4.0.1

References

Classification

Miscellaneous

Original Researcher
Raphael P. Cigana
Submitter
Raphael P. Cigana
Verified
Yes

Timeline

Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)

Other