CVE-2026-32373
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32373 is a Missing Authorization vulnerability in the Cozy Vision SMS Alert Order Notifications WordPress plugin (slug: sms-alert) that allows authenticated attackers to exploit incorrectly configured access control security levels. It affects all versions from n/a through 3.9.0 (inclusive). The vulnerability was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the appropriate permissions before executing certain actions or exposing functionality. This is a network-accessible vulnerability (attack vector: Network) requiring low privileges and no user interaction, consistent with a scenario where a low-privileged authenticated WordPress user (e.g., a subscriber or customer) can invoke plugin endpoints or AJAX handlers that should be restricted to administrators. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).

Impact

Successful exploitation results in limited but meaningful integrity and availability impacts — an authenticated low-privileged attacker can perform unauthorized actions within the plugin's scope, such as modifying plugin settings or disrupting SMS notification functionality, potentially affecting order notification workflows on WooCommerce-based stores. Confidentiality is not directly impacted according to the CVSS assessment. The scope is unchanged, meaning the impact is contained to the vulnerable component rather than enabling broader system compromise (Feedly).

Exploitability

The vulnerability requires only low-level authentication (e.g., a registered WordPress user account), has low attack complexity, and requires no user interaction, making it relatively straightforward to exploit for any authenticated user on an affected site. The EPSS score is approximately 0.017%, indicating a low probability of widespread exploitation in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Feedly).

Mitigation and workarounds

Site administrators should update the SMS Alert Order Notifications plugin to a version beyond 3.9.0 as soon as a patched release is made available by Cozy Vision. In the interim, consider deactivating the plugin if SMS notification functionality is not critical, or restrict WordPress user registration to trusted individuals to reduce the attack surface. Monitor the official WordPress plugin repository and Patchstack advisories for patch availability (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81648CRITICAL10
  • cryptopayment-gateway
NoNoSep 13, 2026
CVE-2026-88793HIGH8.8
  • youram-youtube-embed
NoNoSep 13, 2026
CVE-2026-85129HIGH8.8
  • hoo-companion
NoNoSep 13, 2026
CVE-2026-88802HIGH7.5
  • mobile-dj-manager
NoYesSep 13, 2026
CVE-2026-89050MEDIUM4.3
  • quick-adsense-reloaded
NoYesSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management