CVE-2026-14281
Last modified
CVE-2026-14281 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller.
Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller. This makes it possible for unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. When OTP verification is enabled at signup, the OTP session token (`otp_transient`) is returned in plaintext in the HTTP response body, and the `handle_magic_link_request()` handler marks that token as verified on any unauthenticated GET request containing it without ever checking the OTP code value — making the OTP step trivially bypassable with no inbox or SMS access required.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 101gen | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code | <= 4.8.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-14281?
How severe is CVE-2026-14281?
How do I fix CVE-2026-14281?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14276IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Cl…6.3
- CVE-2026-14277IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an …6.3
- CVE-2026-14278Rejected reason: After further coordination, CVE was determi…
- CVE-2026-14279The Wholesale Market plugin for WordPress is vulnerable to p…8.8
- CVE-2026-1428Single Sign-On Portal System developed by WellChoose has a O…8.8
- CVE-2026-14280The Events Manager – Calendar, Bookings, Tickets, and more! …6.6
- CVE-2026-14282The GoDAM – Organize WordPress Media Library & File Manager …9.8
- CVE-2026-14286Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-14287The 10Web Booster WordPress plugin before 2.33.5 does not c…4.7
- CVE-2026-14289The FacturaONE para WooCommerce con VeriFactu WordPress plug…9
- CVE-2026-1429Single Sign-On Portal System developed by WellChoose has a R…5.4
- CVE-2026-14290The Embed Google Photos album WordPress plugin through 2.2.1…6.8
Are you affected by CVE-2026-14281?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
