1 vulnerability across 1 product scored HIGH or above on August 21, 2026.

  • 🟠 HIGH: 1

🟠 [HIGH] 101gen/automation_web_platform_–_notifications_and_otp_for_woocommerce,_advanced_country_code

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:101gen:automation_web_platform_notifications_and_otp_for_woocommerce_advanced_country_code:*:*:*:*:*:*:*:* (< 4.8.7)

101gen’s Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin versions 4.8.6 and earlier contains a critical authentication bypass vulnerability (CVE-2026-77264, CVSS 9.8). The plugin’s OTP handling function exposes a secret magic login token directly in the response to a publicly accessible request, rather than delivering it exclusively via email, allowing unauthenticated attackers to log in as any user on the site, including administrators.

Any WordPress site running this WooCommerce notification and OTP plugin should treat this as an urgent priority. Site administrators should update to a patched version immediately or deactivate the plugin until a fix is available. Review site access logs for signs of unauthorized logins, and consult the Wordfence advisory for additional technical detail and indicators of compromise.

Vendor Advisory