CVE-2025-3876 | SMS Alert Order Notifications Plugin up to 3.8.1 on WordPress handleWpLoginCreateUserAction authorization
A vulnerability classified as critical has been found in SMS Alert Order Notifications Plugin up to 3.8.1 on WordPress. Affected is the function handleWpLoginCreateUserAction. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-3876. It is possible to launch the attack remotely. There is no exploit available.