WordPress WooCommerce Plugins: Multiple Critical Security Vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656)

This text was generated using artificial intelligence (AI).Update July 29, 2026: In addition, CVE-2025-10656 (CVSS 9.8) was disclosed in the „Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light“ plugin. Due to a lack of authorization checks, this vulnerability allows unauthenticated attackers to gain unauthorized access to administrative functions. See below for details.

Update July 30, 2026: In addition, CVE-2026-3141 (CVSS 9.1) was discovered in the „FormGent – Next-Gen AI Form Builder for WordPress“ plugin. Due to a lack of permission checks, this vulnerability allows unauthenticated attackers to delete any files on the server. A patch is available in version 1.10.0. See below for details.

Update July 31, 2026: In addition, CVE-2026-8457 (CVSS 9.8) was discovered in the „WooCommerce – Social Login“ plugin. The vulnerability allows an authentication bypass in all versions up to and including 2.8.7. See below for details.

On July 28, 2026, a critical vulnerability was discovered in the WordPress plugin „SMS Alert“ with a CVSS score of 9.8 published. The vulnerability, cataloged as CVE-2026-15014 (according to Wordfence CNA), allows an authentication bypass that can lead to a complete account takeover. Affected are e-commerce websites that use the plugin in conjunction with WooCommerce for SMS notifications and one-time password (OTP) verification. Attackers do not need prior access to the system and can exploit the vulnerability remotely.

Are my systems affected? Check now →