CVE-2026-14281: CWE-269 Improper Privilege Management in 101gen Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller. This makes it possible for unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. When OTP verification is enabled at signup, the OTP session token (`otp_transient`) is returned in plaintext in the HTTP response body, and the `handle_magic_link_request()` handler marks that token as verified on any unauthenticated GET request containing it without ever checking the OTP code value — making the OTP step trivially bypassable with no inbox or SMS access required.
AI Analysis
Technical Summary
CVE-2026-14281 affects the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code WordPress plugin versions up to 4.8.6. The vulnerability arises from missing permission enforcement on the publicly accessible REST endpoint `POST /wp-json/wawp/v1/signup/<op>`, and the lack of a key allowlist in the `finish_registration_logic` function. This function copies attacker-controlled `wawp_custom_fields` directly into `update_user_meta()`, enabling attackers to set sensitive meta keys such as `wp_capabilities` and `wp_user_level`. Consequently, unauthenticated attackers can create accounts with administrator roles. Furthermore, when OTP verification is enabled, the OTP session token (`otp_transient`) is returned in plaintext in HTTP responses, and the `handle_magic_link_request()` handler marks the token as verified on any unauthenticated GET request containing it without validating the OTP code, allowing trivial bypass of OTP verification.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to create a new user account with administrator privileges, gaining full control over the affected WordPress site. The OTP verification bypass further facilitates this by allowing attackers to bypass the OTP step without access to the victim's inbox or SMS. This leads to complete compromise of confidentiality, integrity, and availability of the site.
Mitigation Recommendations
No official patch or fix information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to disable the vulnerable plugin or restrict access to the affected REST endpoints if possible. Monitor vendor communications for updates and apply patches promptly once released.
CVE-2026-14281: CWE-269 Improper Privilege Management in 101gen Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller. This makes it possible for unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. When OTP verification is enabled at signup, the OTP session token (`otp_transient`) is returned in plaintext in the HTTP response body, and the `handle_magic_link_request()` handler marks that token as verified on any unauthenticated GET request containing it without ever checking the OTP code value — making the OTP step trivially bypassable with no inbox or SMS access required.
CVSS v3.1
Score 9.8critical
Affected software
101gen
Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14281 affects the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code WordPress plugin versions up to 4.8.6. The vulnerability arises from missing permission enforcement on the publicly accessible REST endpoint `POST /wp-json/wawp/v1/signup/<op>`, and the lack of a key allowlist in the `finish_registration_logic` function. This function copies attacker-controlled `wawp_custom_fields` directly into `update_user_meta()`, enabling attackers to set sensitive meta keys such as `wp_capabilities` and `wp_user_level`. Consequently, unauthenticated attackers can create accounts with administrator roles. Furthermore, when OTP verification is enabled, the OTP session token (`otp_transient`) is returned in plaintext in HTTP responses, and the `handle_magic_link_request()` handler marks the token as verified on any unauthenticated GET request containing it without validating the OTP code, allowing trivial bypass of OTP verification.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to create a new user account with administrator privileges, gaining full control over the affected WordPress site. The OTP verification bypass further facilitates this by allowing attackers to bypass the OTP step without access to the victim's inbox or SMS. This leads to complete compromise of confidentiality, integrity, and availability of the site.
Mitigation Recommendations
No official patch or fix information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to disable the vulnerable plugin or restrict access to the affected REST endpoints if possible. Monitor vendor communications for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-01T01:25:57.917Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab61cb5f7a7c5410676d523
Added to database: 09/25/2026, 07:03:17 UTC
Last enriched: 09/25/2026, 07:18:10 UTC
Last updated: 09/26/2026, 02:42:31 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.