CVE-2026-94256 - SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP
CVE ID :CVE-2026-94256 Published : Oct. 10, 2026, 6:16 a.m. | 7 hours, 13 minutes ago Description :The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as...