
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32373 is a Missing Authorization vulnerability in the Cozy Vision SMS Alert Order Notifications WordPress plugin (slug: sms-alert) that allows authenticated attackers to exploit incorrectly configured access control security levels. It affects all versions from n/a through 3.9.0 (inclusive). The vulnerability was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the appropriate permissions before executing certain actions or exposing functionality. This is a network-accessible vulnerability (attack vector: Network) requiring low privileges and no user interaction, consistent with a scenario where a low-privileged authenticated WordPress user (e.g., a subscriber or customer) can invoke plugin endpoints or AJAX handlers that should be restricted to administrators. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).
Successful exploitation results in limited but meaningful integrity and availability impacts — an authenticated low-privileged attacker can perform unauthorized actions within the plugin's scope, such as modifying plugin settings or disrupting SMS notification functionality, potentially affecting order notification workflows on WooCommerce-based stores. Confidentiality is not directly impacted according to the CVSS assessment. The scope is unchanged, meaning the impact is contained to the vulnerable component rather than enabling broader system compromise (Feedly).
The vulnerability requires only low-level authentication (e.g., a registered WordPress user account), has low attack complexity, and requires no user interaction, making it relatively straightforward to exploit for any authenticated user on an affected site. The EPSS score is approximately 0.017%, indicating a low probability of widespread exploitation in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Feedly).
Site administrators should update the SMS Alert Order Notifications plugin to a version beyond 3.9.0 as soon as a patched release is made available by Cozy Vision. In the interim, consider deactivating the plugin if SMS notification functionality is not critical, or restrict WordPress user registration to trusted individuals to reduce the attack surface. Monitor the official WordPress plugin repository and Patchstack advisories for patch availability (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."