plugin

Automation Web Platform Vulnerabilities

3 known security issues reported for the Automation Web Platform WordPress plugin. Most recent disclosed Aug 20, 2026.

2 critical 1 medium

Running Automation Web Platform on your site? Check whether your installed version is affected.

Scan your site free

Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure

critical

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly acces...

CVSS:
9.8
Affected:
up to 4.8.6
Fix:
No patched version reported
Disclosed:
Aug 20, 2026

CVE-2026-77264 on NVD →

Wawp <= 4.4 - Missing Authorization

medium

The Wawp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.4
Fixed in:
4.5
Disclosed:
Dec 31, 2025

CVE-2025-62141 on NVD →

Wawp < 3.0.18 - Unauthenticated Privilege Escalation

critical

The Wawp OTP Verification, Order Notifications, and Country Code Selector for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to 3.0.18 (exclusive). This makes it possible for unauthenticated attackers to gain access to administrator accounts.

CVSS:
9.8
Affected:
up to 3.0.18
Fixed in:
3.0.18
Disclosed:
Nov 19, 2024

CVE-2024-52475 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database