WordPress WooCommerce Plugins: Multiple Critical Security Vulnerabilities (CVE-2026-15014, CVE-2025-10656)


This text was generated using artificial intelligence (AI).Update July 29, 2026: In addition, CVE-2025-10656 (CVSS 9.8) was disclosed in the „Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light“ plugin. Due to a lack of authorization checks, this vulnerability allows unauthenticated attackers to gain unauthorized access to administrative functions. See below for details.

On July 28, 2026, a critical vulnerability was discovered in the WordPress plugin „SMS Alert“ with a CVSS score of 9.8 published. The vulnerability, cataloged as CVE-2026-15014 (according to Wordfence CNA), allows an authentication bypass that can lead to a complete account takeover. Affected are e-commerce websites that use the plugin in conjunction with WooCommerce for SMS notifications and one-time password (OTP) verification. Attackers do not need prior access to the system and can exploit the vulnerability remotely.

Are my systems affected? Check now →