PT-2026-98362 · WordPress+1 · Advanced Country Code+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress versions prior to 4.8.7
Description
An issue exists due to missing permission enforcement on the publicly accessible REST route
POST /wp-json/wawp/v1/signup/<op> and the absence of a key allowlist in the finish registration logic() function. This allows the wawp custom fields parameter to be copied directly into update user meta(), enabling unauthenticated attackers to set sensitive meta keys such as wp capabilities and wp user level to grant themselves the administrator role and gain full site access. Additionally, when OTP verification is enabled during signup, the otp transient session token is returned in plaintext in the HTTP response body. The handle magic link request() handler marks this token as verified upon any unauthenticated GET request containing it, bypassing the OTP code verification process entirely.Recommendations
Update Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress to a version newer than 4.8.6.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Country Code
Notifications/Otp For Woocommerce