CVE-2026-77264 CRITICAL

CVE-2026-77264: Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure

Vendor 101Gen
Product Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
Weakness CWE-640 · Weak password recovery
Published August 21, 2026
Last update August 21, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.

Explanation of Vulnerability in Simple Terms

02Summary

The Automation Web Platform – Notifications and OTP for WooCommerce plugin contains a weak password recovery mechanism that allows attackers to bypass authentication and gain full control of affected sites. An attacker can reset user passwords without proper verification, leading to account takeover. No authentication or user interaction is required to exploit this vulnerability. All versions up to 4.8.6 are affected.

What an attacker can do

03Attacker Capabilities

Reset user passwords and take over accounts without proper verification.

Potential impact on your site

04Site Impact

Attackers can take over admin and customer accounts, modify site content, and steal data.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 21, 2026 CVE published

Related vulnerabilities

08Related CVE