PT-2026-79312 · WordPress · Notifications/Otp For Woocommerce+1

·

CVE-2026-77264

·

Published

2026-08-21

·

Updated

2026-09-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress versions prior to 4.8.7
Description An authentication bypass exists because the handle email otp return() function returns a secret magic login token directly in the response of a publicly accessible OTP request instead of sending it exclusively to the user's email. This allows unauthenticated attackers to gain access to any account, including administrator accounts, provided they know the target user's email address.
Recommendations Update the plugin to a version newer than 4.8.6. As a temporary mitigation, restrict access to the handle email otp return() function.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77264

Affected Products

Advanced Country Code
Notifications/Otp For Woocommerce