CVE-2026-77264
Received Received - Intake

Authentication Bypass in Notifications and OTP for WooCommerce

Vulnerability report for CVE-2026-77264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Wordfence

Description

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce advanced_country_code to 4.8.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This WordPress plugin has an authentication bypass flaw in versions up to 4.8.6. The handle_email_otp_return() function exposes a secret login token in public OTP requests instead of sending it only to the user's email. Attackers can use this to log in as any user if they know the email address.

Detection Guidance

Check WordPress sites using the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin versions up to 4.8.6. Look for unauthorized login attempts or unexpected OTP responses in server logs.

Impact Analysis

Unauthenticated attackers could gain admin access to your WordPress site if they know an admin's email. This allows full control over the site, including data theft, malware installation, or site defacement.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR (data protection) and HIPAA (health data privacy) requirements. Non-compliance may result in fines or legal penalties.

Mitigation Strategies

Update the plugin to the latest version immediately. If an update is unavailable, disable the plugin temporarily. Review user accounts for unauthorized access and reset credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart