CVE-2026-77264
Last modified
CVE-2026-77264 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 101gen | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code | <= 4.8.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77264?
How severe is CVE-2026-77264?
How do I fix CVE-2026-77264?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77235Missing privilege verification in the secure context cleanup…7.3
- CVE-2026-77236Missing minimum size validation in secure context allocation…7.3
- CVE-2026-77237Missing queue-set type validation in xQueueAddToSet() in the…8.4
- CVE-2026-7724A vulnerability has been found in PrefectHQ prefect up to 3.…5
- CVE-2026-7725A vulnerability was found in PrefectHQ prefect up to 3.6.25.…6.3
- CVE-2026-7726The Layouts for WPBakery plugin for WordPress is vulnerable …6.5
- CVE-2026-7727A vulnerability was determined in Shandong Hoteam Software P…7.3
- CVE-2026-7728A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0…6.3
- CVE-2026-7729A security flaw has been discovered in pixelsock directus-mc…6.3
- CVE-2026-77298SeaweedFS is a distributed storage system for files and blob…8.7
- CVE-2026-7730A weakness has been identified in privsim mcp-test-runner 0.…6.3
- CVE-2026-7731A security vulnerability has been detected in code-projects …6.3
Are you affected by CVE-2026-77264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
