CVE-2026-14281

Published Sep 25, 2026

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-14281 is a privilege escalation vulnerability found in the "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" WordPress plugin, affecting all versions up to and including 4.8.6. The flaw stems from missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>`. This allows unauthenticated attackers to manipulate user metadata by directly passing the `wawp_custom_fields` parameter to WordPress's `update_user_meta()` function without proper validation or a key allowlist. This vulnerability enables an unauthenticated attacker to register a new user account with administrator privileges, thereby gaining full administrative control over the affected WordPress site. Additionally, a related flaw allows for the bypass of the plugin's One-Time Password (OTP) verification step during signup. This occurs because the OTP session token is returned in plaintext, and the `handle_magic_link_request()` function marks the token as verified without actually checking the OTP code value, making the OTP step trivially bypassable.

Description
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller. This makes it possible for unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. When OTP verification is enabled at signup, the OTP session token (`otp_transient`) is returned in plaintext in the HTTP response body, and the `handle_magic_link_request()` handler marks that token as verified on any unauthenticated GET request containing it without ever checking the OTP code value — making the OTP step trivially bypassable with no inbox or SMS access required.
Source
security@wordfence.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-269

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

14

References

Sources include official advisories and independent security research.