CVE-2026-11387Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. This is only vulnerable on sites with OTP verification for password resets enabled, and where the administrator (or other user) has set a phone number for OTP verification.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-07-01); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-01: 2Mentions · 2026-08-24: 1Mentions · 2026-09-09: 1Mentions · 2026-09-10: 1PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-10: 1Exploit Tool / Code · 2026-09-09: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 1Technical Details · 2026-08-24: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-10: 107-0108-2409-0909-10
Signal classification3 categories
Disclosure
240.0%
PoC
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-012
Disclosure1Patch1
2026-08-241
Disclosure1
2026-09-091
PoC1
2026-09-101
PoC1
Full discourse5 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. GitHub: https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP https://t.co/SSXiJE3Rzc

    Post summary

    A critical improper‑authentication flaw (CVE‑2026‑11387) affecting a WordPress plugin is disclosed, with a GitHub link suggesting a PoC is available, but the post lacks details on active exploitation or patches.

    2131472214.6K
    240.7K followersView on X
  • abraxas@abraxas_null
    PoC

    hot 0day, fresh out of the oven! (CVE-2026-11387, Critical 9.8); another WooCommerce banger for you. SMS OTP plugin; forced password reset (even admin!). too hot to handle, don't burn your hands! for research purposes only. https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP https://t.co/9QKWK4TUyQ

    Post summary

    This tweet highlights a critical WooCommerce SMS OTP plugin flaw and provides a GitHub link to proof‑of‑concept code, with no mention of active exploitation or patch availability.

    11152315
    146 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-11387 - critical 🚨 SMS Alert – SMS & OTP for WooCommerce - Privilege Escalation > The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recov... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-11387 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the critical CVE-2026-11387 affecting the SMS Alert – SMS & OTP WooCommerce plugin, indicating a privilege‑escalation flaw, but offers no PoC, exploit details, patch, or evidence of active attacks.

    01041292
    1.3K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-11387 — CVSS 9.8/10 ██████████ The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/DKkemSelTY

    Post summary

    A critical vulnerability (CVE-2026-11387) reported for a WooCommerce plugin is identified with a patch now available, but no PoC or exploit details are provided.

    1000090
    63 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-11387 Unauthenticated Privilege Escalation via Account Takeover in SMS Alert Plugin for WooCommerce https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-11387

    Post summary

    The text announces a new unauthenticated privilege escalation vulnerability (CVE‑2026‑11387) affecting the SMS Alert Plugin for WooCommerce, with no evidence of exploitation, PoC, or patch information.

    0000085
    4.1K followersView on X

Explore more