PatchSiren cyber security CVE debrief
CVE-2026-77264 101gen CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T08:16:44.160Z and has not been modified since then. The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address. Administrators and users should verify installed versions and apply vendor remediation when available. Consider compensating controls such as IP restrictions or two-factor authentication.
- Vendor
- 101gen
- Product
- Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress, especially those with versions up to and including 4.8.6 installed.
Technical summary
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Defensive priority
Unauthenticated attackers can bypass authentication and log in as any user, including administrators, if they know the user's email address.
Recommended defensive actions
- Inventory and verify installed version of Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress
- Restrict access to OTP requests to only authenticated users
- Implement additional monitoring for suspicious login attempts
- Apply vendor remediation when available
- Consider compensating controls such as IP restrictions or two-factor authentication
Evidence notes
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T08:16:44.160Z and has not been modified since then.