Privilege Escalation Vulnerability in WooCommerce Notifications and OTP Plugin by WordPress
CVE-2026-14281
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-14281?
The Automation Web Platform β Notifications and OTP for WooCommerce is exposed to a privilege escalation vulnerability due to inadequate permission enforcement on its REST API. Attackers can exploit this flaw by invoking the publicly accessible POST /wp-json/wawp/v1/signup/<op> endpoint, bypassing essential checks and manipulating sensitive user metadata such as wp_capabilities and wp_user_level. If OTP verification is enabled, attackers can easily bypass this security measure as the OTP session token is returned unchecked in plaintext. This situation allows unauthorized users to register new accounts with elevated privileges, potentially compromising the entire WordPress site.
Affected Version(s)
Automation Web Platform β Notifications and OTP for WooCommerce, Advanced Country Code 0 <= 4.8.6