sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical3
High0
Medium1
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-09-25

Automation Web Platform - Security Vulnerability (CVE-2026-14281)

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which copies the attacker-controlled `wawp_custom_fields` parameter directly into `update_user_meta()` — allowing sensitive meta keys such as `wp_capabilities` and `wp_user_level` to be set by the caller. This makes it possible for unauthenticated attackers to register a…

PLUGIN Automation Web Platform

CVE-2026-14281

CRITICAL CVSS 9.8 2026-09-25
Threat Entry Updated 2026-08-24

Automation Web Platform - Authentication Bypass (CVE-2026-77264)

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.

PLUGIN Automation Web Platform

CVE-2026-77264

CRITICAL CVSS 9.8 2026-08-21