CVE-2026-62106

8.8

Cozy Vision Technologies Pvt. Ltd. · SMS Alert Order Notifications

A privilege escalation vulnerability in the SMS Alert Order Notifications plugin allows authenticated subscribers to gain unauthorized administrative access.

Executive summary

A critical privilege escalation vulnerability in the SMS Alert Order Notifications plugin allows low-privileged subscribers to perform unauthorized administrative actions, posing a severe risk to site integrity.

Vulnerability

This vulnerability, categorized as CWE-266 (Incorrect Privilege Assignment), allows any authenticated subscriber to escalate their privileges to an administrative level. The flaw originates from improper authorization checks within the plugin, enabling users with lower-level access to execute high-privileged functions.

Business impact

The ability for a standard subscriber to escalate privileges to an administrator level creates a significant threat to the confidentiality, integrity, and availability of the WordPress environment. Given the high CVSS score of 8.8, this flaw could lead to full site compromise, unauthorized data exfiltration, or the injection of malicious content. Such an event would result in severe reputational damage and potential regulatory non-compliance regarding data protection.

Remediation

Immediate Action: Update the WordPress SMS Alert Order Notifications plugin to version 4.0.0 or the latest available version provided by the vendor.

Proactive Monitoring: Review WordPress user account logs and audit trails for any suspicious account modifications or unauthorized administrative activity performed by non-admin users.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin-specific administrative endpoints until the update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the severity and the potential for complete administrative takeover, organizations utilizing this plugin must prioritize the update to version 4.0.0 immediately. Administrators should conduct a post-update audit of all user roles to ensure no unauthorized accounts were created or modified while the vulnerability remained unpatched.

More Cozy Vision Technologies Pvt. Ltd. CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by benzdeus | Patchstack Bug Bounty Program, per the CVE Program record.