CVE-2026-66424

WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.


We have discovered 284 live websites that are affected by CVE-2026-66424.

Run a Free Instant Scan




Affected Software

Product  Sms Alert
Category Wordpress Plugins
Vulnerable Domains284 live websites (98% of Sms Alert install base)
Vulnerable Versions
  • from 0 through 3.9.7
Vulnerable Versions Count26 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-266 Incorrect Privilege Assignment



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Aydan Arabadzha | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66424
United States89 websites



India132 websites
Germany15 websites
GB12 websites
Cyprus11 websites
Singapore4 websites
Canada3 websites
Romania3 websites
United Arab Emirates2 websites
Australia2 websites

Website Distribution by TLD

Number of websites using CVE-2026-66424
.com171 websites
.co.uk7 websites
.net7 websites
.org5 websites
.ca2 websites
.com.au2 websites
.de1 websites
.fr1 websites
.it1 websites
.pl1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66424

Top websites that are affected by CVE-2026-66424. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.it Italy*,***,***
************.us India*,***,***
********.com India*,***,***
**********.com United Arab Emirates*,***,***
**************.com Cyprus*,***,***
**********.com United States*,***,***
******.com United States*,***,***
******.com India*,***,***
*****.in India*,***,***
*******.in India*,***,***
See full domain list

FAQ

CVE-2026-66424 is Incorrect Privilege Assignment in Sms Alert
A total of 284 websites have been identified as vulnerable to CVE-2026-66424, based on global website indexing conducted by WebTechSurvey.
The Sms Alert is affected by the CVE-2026-66424 vulnerability.
Sms Alert versions up to and including 3.9.7 are vulnerable to CVE-2026-66424.