Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Published: 2026-08-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin’s OTP authentication function exposes a secret magic login token in the response to a publicly accessible OTP request. This allows an unauthenticated attacker who knows a user’s e‑mail address to retrieve that token and authenticate as that user, including administrators. The flaw is a classic authentication bypass, identified as CWE‑640.

Affected Systems

WordPress sites that have installed Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin, versions up to and including 4.8.6. Any site using these plugin versions is vulnerable.

Risk and Exploitability

With a Base Score of 9.8, the vulnerability is considered critical. The EPSS score is not available, but the absence of a KEV listing does not reduce the likelihood of exploitation. Attackers can trigger the flaw remotely and without prior authentication, by making an HTTP request to the OTP endpoint with the target user’s e‑mail address. Knowledge of the user’s e‑mail is the single prerequisite, after which the attacker obtains the magic token and can log in instantly.

Generated by OpenCVE AI on August 21, 2026 at 09:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Automation Web Platform plugin to the latest version that removes the token disclosure, or to at least 4.8.7 if available.
  • If an upgrade is not immediately possible, block the public access to the OTP endpoint or disable OTP functionality until a patch is applied.
  • Implement additional controls such as rate limiting or reCAPTCHA on the OTP request form to reduce the risk of automated abuse.

Generated by OpenCVE AI on August 21, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared 101gen
101gen automation Web Platform – Notifications And Otp For Woocommerce, Advanced Country Code
Wordpress
Wordpress wordpress
Vendors & Products 101gen
101gen automation Web Platform – Notifications And Otp For Woocommerce, Advanced Country Code
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Title Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

101gen Automation Web Platform – Notifications And Otp For Woocommerce, Advanced Country Code
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-21T10:55:25.315Z

Reserved: 2026-08-20T19:05:11.939Z

Link: CVE-2026-77264

cve-icon Vulnrichment

Updated: 2026-08-21T10:55:19.822Z

cve-icon NVD

Status : Received

Published: 2026-08-21T08:16:44.160

Modified: 2026-08-21T11:17:06.207

Link: CVE-2026-77264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:08:04Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password