A vulnerability was found in cozyvision1 SMS Alert Plugin up to 3.9.7 on WordPress. It has been rated as critical. This affects the function processRegistration. This manipulation of the argument billing_phone causes improper authentication.

This vulnerability appears as CVE-2026-15014. The attack may be initiated remotely. There is no available exploit.