← Terug naar overzicht

CVE-2026-77264 describes a critical authentication bypass vulnerability in the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress, affecting versions up to and including 4.8.6. The vulnerability exists in the handle_email_otp_return() function, which incorrectly returns the secret magic login token directly in the HTTP response to a publicly accessible OTP request, instead of delivering it exclusively to the user's email. This design flaw allows unauthenticated attackers to capture the token and use it to log in as any registered user on the site, including administrators, as long as they know the target's email address. The attack requires no prior authentication and can lead to full site compromise. Site owners using the affected plugin versions are urged to update immediately to a patched version.

Affected products

  • Advanced Country Code plugin for WordPress (up to and including version 4.8.6)
  • Automation Web Platform – Notifications and OTP for WooCommerce

Related CVE's

  • CVE-2026-77264

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities