CVE-2026-14281
No known patch is available for this vulnerability.
The affected plugin has not been updated on WordPress.org since before this CVE was disclosed; the latest installable version is still vulnerable. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route POST /wp-json/wawp/v1/signup/ and the absence of a key allowlist in the finish_registration_logic function, which copies the attacker-controlled wawp_custom_fields parameter directly into update_user_meta() — allowing sensitive meta keys such as wp_capabilities and wp_user_level to be set by the caller. This makes it possible for unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. When OTP verification is enabled at signup, the OTP session token (otp_transient) is returned in plaintext in the HTTP response body, and the handle_magic_link_request() handler marks that token as verified on any unauthenticated GET request containing it without ever checking the OTP code value — making the OTP step trivially bypassable with no inbox or SMS access required.
Affected products
1- Range: <=4.8.6
Patches
Vulnerability mechanics
References
14- plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/api/class-wawp-rest-settings-api.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/api/class-wawp-rest-settings-api.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/auth-services/class-wawp-otp-service.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/auth-services/class-wawp-otp-service.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/auth-services/class-wawp-signup.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/tags/4.8.6/includes/auth-services/class-wawp-signup.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/trunk/includes/api/class-wawp-rest-settings-api.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/trunk/includes/api/class-wawp-rest-settings-api.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/trunk/includes/auth-services/class-wawp-otp-service.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/trunk/includes/auth-services/class-wawp-otp-service.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/trunk/includes/auth-services/class-wawp-signup.phpnvd
- plugins.trac.wordpress.org/browser/automation-web-platform/trunk/includes/auth-services/class-wawp-signup.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/f17d3e43-29c6-4c80-912d-53ceda3fcb5dnvd
News mentions
0No linked articles in our index yet.