CVE-2026-77264 (matched: wordpress)

  • Friday, 21st August, 2026
  • 10:09am

A security flaw has been identified in the "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" plugin for WordPress, affecting all versions up to and including 4.8.6.

The flaw is an authentication bypass issue. Normally, this plugin sends secret one-time login codes only to the email address linked to a user account, but a bug causes these codes to be included in public responses to requests for one-time passwords.

This allows unauthenticated attackers to log in as any user on your site if they know that user's email address, including administrator accounts. If exploited, this could let an attacker take full control of your WordPress site, make unauthorized changes to content or settings, or access sensitive information stored on the site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-77264

« Back