CVE-2026-66424
9.8Cozy Vision Technologies Pvt. · SMS Alert Order Notifications
An unauthenticated privilege escalation vulnerability in the SMS Alert Order Notifications plugin for WordPress versions 3.9.7 and below allows attackers to improperly assign privileges.
Executive summary
A critical privilege escalation vulnerability in the SMS Alert Order Notifications WordPress plugin allows unauthenticated attackers to gain unauthorized administrative access.
Vulnerability
This vulnerability is caused by incorrect privilege assignment (CWE-266), which allows unauthenticated users to escalate their access levels. The flaw resides within the plugin's core functionality, enabling unauthorized administrative actions.
Business impact
Exploitation of this vulnerability allows an attacker to gain administrative privileges on the host WordPress site. This results in complete loss of site control, potential data theft, and the ability to inject malicious code into the site environment. The CVSS score of 9.8 confirms the critical nature of this vulnerability.
Remediation
Immediate Action: Update the SMS Alert Order Notifications plugin to version 3.9.8 or later immediately.
Proactive Monitoring: Review WordPress user management logs for unauthorized account modifications or account creation events.
Compensating Controls: Use a Web Application Firewall to block suspicious traffic patterns directed at WordPress plugin endpoints and restrict access to the WordPress dashboard.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for complete site compromise, administrators must treat this vulnerability as a high priority. Ensure that the plugin is updated to the latest version (3.9.8) immediately to neutralize the risk of unauthorized administrative access.