Privilege Escalation Vulnerability in WooCommerce Notifications and OTP Plugin by WordPress
CVE-2026-14281

9.8CRITICAL

What is CVE-2026-14281?

The Automation Web Platform – Notifications and OTP for WooCommerce is exposed to a privilege escalation vulnerability due to inadequate permission enforcement on its REST API. Attackers can exploit this flaw by invoking the publicly accessible POST /wp-json/wawp/v1/signup/<op> endpoint, bypassing essential checks and manipulating sensitive user metadata such as wp_capabilities and wp_user_level. If OTP verification is enabled, attackers can easily bypass this security measure as the OTP session token is returned unchecked in plaintext. This situation allows unauthorized users to register new accounts with elevated privileges, potentially compromising the entire WordPress site.

Affected Version(s)

Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code 0 <= 4.8.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jiemook
.