The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user,...
Description
The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user, including administrators.
AI Analyst Comment
Remediation
Update 101gen Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: 101gen
PRODUCT: Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
AFFECTED_VERSIONS: 0 through 4.8.6
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user, including administrators.
Executive Summary:
A critical authentication bypass vulnerability in the 101gen Automation Web Platform plugin allows unauthenticated attackers to gain full administrative access to affected WordPress sites.
Vulnerability Details
CVE-ID: CVE-2026-77264
Affected Software: 101gen Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
Affected Versions: 0 through 4.8.6
Vulnerability: This is an authentication bypass vulnerability stemming from the improper handling of OTP tokens in the handle_email_otp_return() function. The application inadvertently returns secret magic login tokens in the response to public requests, which enables unauthenticated attackers to perform account takeovers.
Business Impact
Successful exploitation of this vulnerability permits full administrative control over the compromised WordPress installation. This leads to complete data compromise, unauthorized modification of site content, and potential injection of malicious scripts into the environment, which carries a severe risk of long-term reputational and operational damage. The CVSS score of 9.8 reflects the ease of exploitation and the high impact on confidentiality, integrity, and availability.
Remediation Plan
Immediate Action: Discontinue the use of the plugin or disable the OTP functionality until a vendor-supplied security update is released and verified.
Proactive Monitoring: Review web server and WordPress authentication logs for unusual login patterns or multiple failed attempts originating from unexpected IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at OTP-related endpoints and monitor for anomalous traffic patterns.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the exposure of authentication tokens in plain text responses.
Analyst Recommendation
This is a high-severity flaw that requires immediate attention. Given that no patch is currently identified, site administrators should prioritize disabling the affected plugin functionality to prevent unauthorized access. Monitor your environment closely for any signs of account takeover or unexpected administrative activity until a secure version is available.