Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

Published September 11, 2026 CVE-2026-62106

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

Severity
HighCVSS 3.1 · 8.8 · patchstack.com
Fix
Fixed in 4.0.0Fix recorded today
Affected versions
through 3.9.9
Weakness
CWE-266
Affects
SMS Alert Order Notifications
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: total
EU ID
EUVD-2026-76213ENISA vulnerability database

What to do

Update to 4.0.0 or later.

Technical details

Affected software: SMS Alert Order NotificationsWordPress plugin by Cozy Vision Technologies Pvt. Ltd

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator