AI description
CVE-2026-14281 is a privilege escalation vulnerability found in the "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" WordPress plugin, affecting all versions up to and including 4.8.6. The flaw stems from missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>`. This allows unauthenticated attackers to manipulate user metadata by directly passing the `wawp_custom_fields` parameter to WordPress's `update_user_meta()` function without proper validation or a key allowlist. This vulnerability enables an unauthenticated attacker to register a new user account with administrator privileges, thereby gaining full administrative control over the affected WordPress site. Additionally, a related flaw allows for the bypass of the plugin's One-Time Password (OTP) verification step during signup. This occurs because the OTP session token is returned in plaintext, and the `handle_magic_link_request()` function marks the token as verified without actually checking the OTP code value, making the OTP step trivially bypassable.
- Description
- The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller. This makes it possible for unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. When OTP verification is enabled at signup, the OTP session token (`otp_transient`) is returned in plaintext in the HTTP response body, and the `handle_magic_link_request()` handler marks that token as verified on any unauthenticated GET request containing it without ever checking the OTP code value — making the OTP step trivially bypassable with no inbox or SMS access required.
- Source
- security@wordfence.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-269
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
14
‼️ CVE-2026-14281: Unauthenticated Privilege Escalation Vulnerability in the WAWP WordPress Plugin CVE Published: September 24, 2026 PoC Published: September 25, 2026 GitHub PoC: https://t.co/oGq3JvaaIr
@DarkWebInformer
27 Sept 2026
9285 Impressions
11 Retweets
53 Likes
15 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-100382 CVE-2026-100075 CVE-2026-14281 CVE-2026-92161 CVE-2026-92609 ..🧵👇
@exploitgrid
26 Sept 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerabilidades en Complementos para WordPress ❗ CVE-2026-93399 ❗ CVE-2026-89055 ❗ CVE-2026-14281 ➡️ Más info: https://t.co/EQ5wJWh9K3 https://t.co/BLPWLXguJH
@CERTpy
25 Sept 2026
149 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-14281 — WAWP (Automation Web Platform) WordPress ≤ 4.8.6 Unauth REST signup: wawp_custom_fields → update_user_meta with no allowlist → wp_capabilities = administrator. CVSS 9.8 Critical https://t.co/b7NA7OoyVy #WordPress #CVE #Infosec
@pocbitorg
25 Sept 2026
21 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-14281 — WAWP (Automation Web Platform) WordPress ≤ 4.8.6 Unauth REST signup: wawp_custom_fields → update_user_meta with no allowlist → wp_capabilities = administrator. CVSS 9.8 Critical https://t.co/uC2qepX7DR #WordPress #CVE #Infosec
@murrezsec
25 Sept 2026
78 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes