CVE-2026-11387 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-11387 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-11387 is a critical authentication bypass / privilege escalation issue in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery affecting all versions up to and including 3.9.5. An unauthenticated attacker can change a user’s email address, including an administrator’s, and then use the password reset flow to take over the account. This is only exploitable on sites where OTP verification for password resets is enabled and the target user has a phone number configured for OTP verification.
Severity: CRITICAL (CVSS 9.8) | KEV: No | Exploited in the wild: No
If you run a small WordPress shop, membership site, or client portal, treat this as a full admin takeover risk until patched.
Immediate Action
- Upgrade immediately to the first fixed release from the vendor. If you do not know the safe version yet, use the latest available release and confirm it is above 3.9.5. Vendor advisory / changelog
- Disable OTP-based password reset in the plugin until you have confirmed the fix is installed and working.
- Remove phone numbers from administrator and privileged accounts if OTP reset is not required for business operations.
- Rotate credentials for WordPress admins, hosting panels, database users, and any API keys stored in wp-config.php if you suspect exposure.
- Review recent account changes for unexpected email updates, password resets, or new admin users.
- Rollback guidance: if the upgrade breaks checkout or OTP flows, roll back only after disabling the vulnerable feature and documenting the exposure window.
Affected Versions
sms-alert-woocommerce-otp@<=3.9.5vulnerablesms-alert-woocommerce-otp@>=FIXED_VERSION_TODOsafe- Condition required: OTP verification for password resets enabled, and target user has a phone number set for OTP verification
Resolution Guide
WordPress / plugin update: update from the admin dashboard or via WP-CLI.
wp plugin update sms-alert-woocommerce-otp
wp plugin status sms-alert-woocommerce-otp
If you manage WordPress in Git or a deployment pipeline: pin the plugin to the fixed version once known.
# TODO: replace FIXED_VERSION_TODO with the first patched release
composer require vendor/package:FIXED_VERSION_TODO
JavaScript ecosystems: not typically applicable unless you vendor the plugin or a related service wrapper, but if your app depends on a package with the same vulnerable logic, update it directly.
npm i package@FIXED_VERSION_TODO
yarn add package@FIXED_VERSION_TODO
pnpm add package@FIXED_VERSION_TODO
Python: if you use a management script or integration package, upgrade it explicitly.
pip install --upgrade package==FIXED_VERSION_TODO
pipx upgrade package
Java: update the dependency in Maven or Gradle if present.
<dependency>
<groupId>TODO.group</groupId>
<artifactId>TODO-artifact</artifactId>
<version>FIXED_VERSION_TODO</version>
</dependency>
implementation("TODO.group:TODO-artifact:FIXED_VERSION_TODO")
Linux package managers: if packaged by your distro or vendor repo, update the package and restart the site stack.
sudo apt update && sudo apt install --only-upgrade TODO-package
sudo yum update TODO-package
Docker: rebuild using a patched image tag and redeploy.
docker pull TODO-image:FIXED_VERSION_TODO
docker compose up -d --force-recreate
Hardening:
# Disable OTP password reset until patched
# TODO: exact setting name may vary by plugin version
define('SMS_ALERT_DISABLE_OTP_RESET', true);
# Example operational control: remove phone numbers from privileged users
# and require manual admin-assisted password resets temporarily.
Minimal fix pattern for developers: ensure any profile update or email change is authorized before applying it.
// Pseudocode: verify the current authenticated user owns the account
if (!current_user_can('edit_user', $target_user_id)) {
return new WP_Error('forbidden', 'Unauthorized');
}
update_user_meta($target_user_id, 'email', $new_email);
Detection & Verification
Check the installed version:
wp plugin list --name=sms-alert-woocommerce-otp
grep -R "Version:" wp-content/plugins/sms-alert-woocommerce-otp/*.php
Look for risky configuration: search for OTP reset settings and phone-based verification fields.
grep -RniE "otp.*reset|password reset|phone number|verification" wp-content/plugins/sms-alert-woocommerce-otp/
Dependency auditors: if the plugin is mirrored in your build or container image, scan the artifact for the vulnerable version string.
grep -R "3.9.5" /var/www/html/wp-content/plugins/sms-alert-woocommerce-otp/
Verify the fix:
wp plugin update sms-alert-woocommerce-otp --dry-run
wp plugin status sms-alert-woocommerce-otp
After patching, test the password reset flow with a non-admin account and confirm the plugin refuses unauthorized email changes. Also confirm that privileged accounts cannot be modified without valid authentication and authorization.
Risk and Impact
This flaw can let an unauthenticated attacker seize control of administrator accounts, which means full WordPress compromise: content tampering, malicious redirects, new admin creation, plugin/theme installation, and possible access to connected payment or customer data. For small teams, the blast radius is often the entire site plus any systems reachable from stored credentials or admin sessions. Even though there are no known active exploits yet, the attack path is straightforward enough that patching should be treated as urgent.