CVE-2025-66086
Description
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in SMS Alert plugin up to v3.8.8 allows unauthenticated attackers to exploit misconfigured access controls, potentially leading to privilege escalation.
The SMS Alert Order Notifications plugin for WordPress (versions up to and including 3.8.8) suffers from a missing authorization vulnerability [1]. This means that certain functions within the plugin do not properly verify that the user has the required privileges, effectively allowing access controls to be bypassed.
An attacker can exploit this vulnerability without needing any authentication, simply by sending crafted requests to the vulnerable endpoints. Since the vulnerability affects a widely-used plugin, it is likely to be targeted in automated mass-exploit campaigns aimed at compromising thousands of WordPress sites [1].
Successful exploitation could allow an unprivileged attacker to perform actions that should be restricted to higher-privileged users, such as modifying order notifications or accessing sensitive data. The exact impact depends on the specific missing authorization checks, but it can lead to unauthorized access and potential site compromise.
To mitigate this issue, users must update the plugin to version 3.8.9 or later, which contains the necessary security fixes. No other workarounds have been provided, so updating is the recommended course of action [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.8.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.