CVE-2026-77264

9.8

101gen · Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code

The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user, including administrators.

Executive summary

A critical authentication bypass vulnerability in the 101gen Automation Web Platform plugin allows unauthenticated attackers to gain full administrative access to affected WordPress sites.

Vulnerability

This is an authentication bypass vulnerability stemming from the improper handling of OTP tokens in the handle_email_otp_return() function. The application inadvertently returns secret magic login tokens in the response to public requests, which enables unauthenticated attackers to perform account takeovers.

Business impact

Successful exploitation of this vulnerability permits full administrative control over the compromised WordPress installation. This leads to complete data compromise, unauthorized modification of site content, and potential injection of malicious scripts into the environment, which carries a severe risk of long-term reputational and operational damage. The CVSS score of 9.8 reflects the ease of exploitation and the high impact on confidentiality, integrity, and availability.

Remediation

Immediate Action: Discontinue the use of the plugin or disable the OTP functionality until a vendor-supplied security update is released and verified.

Proactive Monitoring: Review web server and WordPress authentication logs for unusual login patterns or multiple failed attempts originating from unexpected IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at OTP-related endpoints and monitor for anomalous traffic patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This is a high-severity flaw that requires immediate attention. Given that no patch is currently identified, site administrators should prioritize disabling the affected plugin functionality to prevent unauthorized access. Monitor your environment closely for any signs of account takeover or unexpected administrative activity until a secure version is available.