CVE-2026-59540
Cozy Vision Technologies Pvt. · SMS Alert Order Notifications
The SMS Alert Order Notifications WordPress plugin contains an unauthenticated privilege escalation vulnerability that allows attackers to gain unauthorized administrative access.
Executive summary
An unauthenticated privilege escalation vulnerability in the SMS Alert Order Notifications plugin poses a critical risk to WordPress site integrity.
Vulnerability
The plugin fails to properly restrict access to sensitive functions, resulting in an incorrect privilege assignment (CWE-266). This allows an unauthenticated attacker to escalate their privileges within the WordPress environment.
Business impact
Successful exploitation grants an attacker administrative control over the affected WordPress installation. This can lead to total site compromise, including the ability to install malicious plugins, exfiltrate user data, or deface the web presence. The CVSS score of 9.8 reflects the high severity of full administrative account takeover.
Remediation
Immediate Action: Update the SMS Alert Order Notifications plugin to version 3.9.7 or later.
Proactive Monitoring: Monitor WordPress user accounts for the creation of unauthorized administrative users or suspicious changes to existing account permissions.
Compensating Controls: If an update cannot be applied immediately, deactivate the plugin to prevent exploitation until the patch is implemented.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability is critical due to the potential for total site takeover. Administrators should verify their current version and update to 3.9.7 immediately to remove the escalation vector.