PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77264 101gen CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T08:16:44.160Z and has not been modified since then. The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address. Administrators and users should verify installed versions and apply vendor remediation when available. Consider compensating controls such as IP restrictions or two-factor authentication.

Vendor
101gen
Product
Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Administrators and users of the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress, especially those with versions up to and including 4.8.6 installed.

Technical summary

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.

Defensive priority

Unauthenticated attackers can bypass authentication and log in as any user, including administrators, if they know the user's email address.

Recommended defensive actions

  • Inventory and verify installed version of Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress
  • Restrict access to OTP requests to only authenticated users
  • Implement additional monitoring for suspicious login attempts
  • Apply vendor remediation when available
  • Consider compensating controls such as IP restrictions or two-factor authentication

Evidence notes

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T08:16:44.160Z and has not been modified since then.