The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network.
This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 08 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
Title SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T10:59:17.605Z

Reserved: 2026-09-21T09:02:50.281Z

Link: CVE-2026-94258

cve-icon Vulnrichment

Updated: 2026-10-08T10:52:01.416Z

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:47.143

Modified: 2026-10-08T11:16:47.907

Link: CVE-2026-94258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:15:08Z

Weaknesses