Refine your search
1 vulnerability found for Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code by 101gen
CVE-2026-77264 (GCVE-0-2026-77264)
Vulnerability from cvelistv5
Published
2026-08-21 07:39
Modified
2026-08-21 10:55
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-640 - Weak Password Recovery Mechanism for Forgotten Password
Summary
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| 101gen | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code |
Version: 0 ≤ 4.8.6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77264",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T10:55:03.350115Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T10:55:25.315Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Automation Web Platform \u2013 Notifications and OTP for WooCommerce, Advanced Country Code",
"vendor": "101gen",
"versions": [
{
"lessThanOrEqual": "4.8.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "RIA Labs"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Automation Web Platform \u2013 Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user\u0027s email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user\u0027s email address."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-640",
"description": "CWE-640 Weak Password Recovery Mechanism for Forgotten Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T07:39:24.523Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e473896-d94c-4f6a-a96c-bb90902532cc?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/auth-services/class-wawp-otp-login.php#L1218"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-08-20T19:06:41.000Z",
"value": "Disclosed"
}
],
"title": "Automation Web Platform \u003c= 4.8.6 - Unauthenticated Authentication Bypass via \u0027otp_transient\u0027 Token Disclosure"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-77264",
"datePublished": "2026-08-21T07:39:24.523Z",
"dateReserved": "2026-08-20T19:05:11.939Z",
"dateUpdated": "2026-08-21T10:55:25.315Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}