CVE-2026-11387 is an unauthenticated privilege-escalation vulnerability in the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery WordPress plugin through version 3.9.5. The plugin fails to properly validate a user's identity before permitting changes to account details. An attacker can change the email address associated with an arbitrary account and use the password-reset process to establish a new password, resulting in account takeover. Administrator accounts can be targeted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains a standalone Python 3 proof-of-concept, a README, and a basic Python-oriented .gitignore. The sole executable, CVE-2026-11387-WooCommerce-SMS-OTP-Abraxas-Labs.py, targets CVE-2026-11387 in the SMS Alert WordPress plugin through version 3.9.5. It accepts a target base URL, victim username, and optional replacement password; if omitted, it uses the hardcoded default abr4x4s#L4b5. The script uses requests with a browser-like User-Agent and a 30-second timeout. The exploit initiates the lost-password flow against WooCommerce and native WordPress paths, then sends password-change form submissions to multiple likely routing locations. The critical request supplies option=smsalert-change-password-form and new/confirmation password fields but no OTP. It treats a redirect containing password-reset=true as success, and otherwise posts the new credentials to wp-login.php as a takeover check. The issue is described as an improper-authentication flaw: the plugin applies the password change without binding it to a completed OTP verification, nonce, authenticated session, or other proof that the requester owns the named account. No fixed victim host, IP address, command-and-control service, shell payload, persistence mechanism, or data-exfiltration behavior is present. All attack traffic is sent only to the operator-provided base URL. The README documents the affected conditions, impact, mitigation by upgrading to SMS Alert 3.9.6 or later, and notes that administrator-account takeover can lead to complete WordPress site compromise.
Repository contains a single substantial Python exploit script, CVE-2026-11387.py, plus a README and .gitignore. The exploit targets CVE-2026-11387 in the WordPress plugin SMS Alert – OTP Verification for WooCommerce (slug: sms-alert), affecting versions up to 3.9.5. The vulnerability is an unauthenticated arbitrary password reset caused by missing session-state validation in the plugin's password reset handler: the attacker first triggers the OTP challenge to seed $_SESSION['user_login'] for a chosen victim, then submits option=smsalert-change-password-form with a new password, bypassing OTP verification entirely. The Python script is an operational exploit rather than a simple detector. Based on the visible code and README, it supports multiple modes: single-target exploitation, username enumeration, mass exploitation with concurrent threads, and fingerprint-only scanning. It builds persistent requests sessions, supports optional proxy rotation, retries transient network failures, and uses the same session across requests to preserve cookies needed for the exploit chain. The script also includes console output helpers and result logging. Primary exploit capabilities include: checking target reachability with HTTP/HTTPS handling, fingerprinting plugin version via readme.txt, enumerating usernames through common WordPress discovery methods (as described in the README), triggering the vulnerable lost-password OTP flow, resetting the victim password to an attacker-controlled value (default Tmp_P0c_2026!Aa), and verifying compromise by logging into /wp-login.php and checking for a wordpress_logged_in_* cookie. The README also documents mass mode input/output behavior, including targets.txt and CSV/result file generation. Fingerprintable endpoints and artifacts are mostly target-relative rather than hardcoded external infrastructure: /my-account/lost-password/ for both OTP trigger and password reset, /wp-login.php for login verification, plugin readme.txt for version detection, and local files such as scan_results/CVE-2026-11387_success.txt and targets.txt. No obvious attacker-controlled C2, hardcoded IPs, or external domains are present in the provided content.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A password-reset bypass vulnerability in the SMS Alert WordPress component/plugin that appears to allow resetting a user's password by supplying a username and new password.
An unauthenticated privilege escalation and account takeover vulnerability in the SMS Alert WordPress plugin caused by improper validation of user identity before allowing account detail changes and password reset workflow abuse.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.