Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-77264: Automation Web Platform up to 4.8.6 lets attackers log in without password

CVE-2026-77264 · published 14 days ago
Summary

The Automation Web Platform for WordPress (including the Notifications and OTP for WooCommerce and Advanced Country Code extensions) can reveal a secret login token when anyone requests a one‑time password. Because the token is returned in the web response instead of only being emailed, anyone who knows a user's email address can use it to sign in as that user, even as an administrator. Update the platform to the latest version or apply a patch that stops the token from being exposed in public responses.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
101gen automation web platform – notifications and otp for woocommerce, advanced country code <= 4.8.6
Original advisory text
Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-640Weak Password Recovery Mechanism for Forgotten Password
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen21 Aug 2026
Sources
CVE-2026-77264 · MITRE
Monitor software like this
Free during beta