What the vulnerability does
01Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Explanation of Vulnerability in Simple Terms
02Summary
The Automation Web Platform – Notifications and OTP for WooCommerce plugin contains a weak password recovery mechanism that allows attackers to bypass authentication and gain full control of affected sites. An attacker can reset user passwords without proper verification, leading to account takeover. No authentication or user interaction is required to exploit this vulnerability. All versions up to 4.8.6 are affected.
What an attacker can do
03Attacker Capabilities
Reset user passwords and take over accounts without proper verification.
Potential impact on your site
04Site Impact
Attackers can take over admin and customer accounts, modify site content, and steal data.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 21, 2026
CVE published