CVE-2026-94256: CWE-287 Improper Authentication in SMS Alert
Description
The SMS Alert WordPress plugin versions 4.0.0 up to but not including 4.0.1 contains an authentication flaw. It does not verify that the account being logged into matches the one associated with the verified one-time code. This allows unauthenticated attackers to sign in as any user with a stored phone number, including administrators, by completing a code challenge on a phone they control.
Affected software
SMS Alert
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94256 is an improper authentication vulnerability (CWE-287) in the SMS Alert WordPress plugin before version 4.0.1. The flaw arises because the plugin fails to confirm that the user account attempting login corresponds to the account linked to the verified one-time code sent via SMS. As a result, an attacker who controls a phone number stored for any user can complete the code challenge and gain unauthorized access to that user's account, including accounts with administrative privileges.
Potential Impact
Successful exploitation allows an unauthenticated attacker to bypass authentication and sign in as any user with a stored phone number, including administrators. This can lead to full account compromise, unauthorized access to sensitive data, and potential site takeover.
Mitigation Recommendations
Upgrade the SMS Alert WordPress plugin to version 4.0.1 or later, where this authentication flaw is fixed. No other mitigation is indicated by the vendor advisory. Patch status is not explicitly stated but the affected versions are limited to >=4.0.0 <4.0.1, implying 4.0.1 contains the fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-21T09:02:42.996Z
- State
- PUBLISHED
Threat ID: 6ac9d55a2cdf04f6560b02b8
Added to database: 10/10/2026, 06:04:10 UTC
Last enriched: 10/10/2026, 06:18:38 UTC
Last updated: 10/10/2026, 06:18:56 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.