Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure
critical
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly acces...
- CVSS:
- 9.8
- Affected:
- up to 4.8.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 20, 2026
CVE-2026-77264 on NVD →
Wawp <= 4.4 - Missing Authorization
medium
The Wawp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.4
- Fixed in:
- 4.5
- Disclosed:
- Dec 31, 2025
CVE-2025-62141 on NVD →
Wawp < 3.0.18 - Unauthenticated Privilege Escalation
critical
The Wawp OTP Verification, Order Notifications, and Country Code Selector for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to 3.0.18 (exclusive). This makes it possible for unauthenticated attackers to gain access to administrator accounts.
- CVSS:
- 9.8
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.18
- Disclosed:
- Nov 19, 2024
CVE-2024-52475 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database