WordPress Plugin Vulnerabilities

SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile

Description

The plugin does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.

Proof of Concept

Affects Plugins

Fixed in 3.9.8

References

Classification

Miscellaneous

Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 13 days ago)
Added
2026-07-20 (about 12 days ago)
Last Updated
2026-07-31 (about 1 day ago)

Other