CVE-2026-94257 - SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
CVE ID :CVE-2026-94257 Published : Oct. 10, 2026, 6:16 a.m. | 7 hours, 13 minutes ago Description :The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset, allowing...