{"api_version":"1","generated_at":"2026-10-09T00:39:54+00:00","cve":"CVE-2026-94258","urls":{"html":"https://cve.report/CVE-2026-94258","api":"https://cve.report/api/cve/CVE-2026-94258.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-94258","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-94258"},"summary":{"title":"SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions","description":"The SMS Alert  WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network.\nThis affects multisite only, and requires the SMS Alert  WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-10-08 06:16:47","updated_at":"2026-10-08 20:51:18"},"problem_types":["CWE-200","CWE-200 Information Exposure","CWE-200 CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"2.7","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"2.7","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://wpscan.com/vulnerability/25af3225-3b4b-4882-9af8-ab24597f9be2/","name":"https://wpscan.com/vulnerability/25af3225-3b4b-4882-9af8-ab24597f9be2/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-94258","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94258","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"SMS Alert","version":"affected 3.6.4 4.0.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Muni Nitish Kumar Yaddala","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"94258","cve":"CVE-2026-94258","epss":"0.001390000","percentile":"0.028260000","score_date":"2026-10-08","updated_at":"2026-10-09 00:01:23"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-94258","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-08T10:54:32.947490Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T10:59:17.605Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"SMS Alert","vendor":"Unknown","versions":[{"lessThan":"4.0.1","status":"affected","version":"3.6.4","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Muni Nitish Kumar Yaddala"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The SMS Alert  WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network.\nThis affects multisite only, and requires the SMS Alert  WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T06:00:09.230Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/25af3225-3b4b-4882-9af8-ab24597f9be2/"}],"source":{"discovery":"EXTERNAL"},"title":"SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Actions","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-94258","datePublished":"2026-10-08T06:00:09.230Z","dateReserved":"2026-09-21T09:02:50.281Z","dateUpdated":"2026-10-08T10:59:17.605Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 06:16:47","lastModifiedDate":"2026-10-08 20:51:18","problem_types":["CWE-200","CWE-200 Information Exposure","CWE-200 CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-08T10:54:32.947490Z","id":"CVE-2026-94258","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"94258","Ordinal":"1","Title":"SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disc","CVE":"CVE-2026-94258","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"94258","Ordinal":"1","NoteData":"The SMS Alert  WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network.\nThis affects multisite only, and requires the SMS Alert  WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.","Type":"Description","Title":"SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disc"}]}}}