CVE-2026-77264Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Technical Details · 2026-08-21: 308-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Digital Warfare@Digital_Warfare
    Disclosure

    🔴 CVE-2026-77264 exposes a critical WordPress OTP. • No prior login required • Versions through 4.8.6 affected 👉 Partner with Digital Warfare today and discover why organizations trust us to identify WordPress exposure. Read more: https://www.linkedin.com/pulse/critical-wordpress-authentication-bypass-exposes-accounts-knight-umgye https://t.co/tB5qH1amrC

    Post summary

    The post announces CVE‑2026‑77264 as a critical authentication bypass for WordPress up to 4.8.6, providing basic technical details but no PoC or exploit information.

    0000024
    59 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-77264 Authentication Bypass in WooCommerce Advanced Country Code Plugin... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-77264 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A brief announcement notes an authentication bypass vulnerability (CVE‑2026‑77264) in the WooCommerce Advanced Country Code Plugin, with links to details and alerts—but no PoC, exploit, patch, or active exploitation information.

    00000114
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-77264 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up … https://www.cve.org/CVERecord?id=CVE-2026-77264

    Post summary

    The entry cites CVE‑2026‑77264, indicating an authentication bypass vulnerability in two WordPress plugins; it provides the vulnerability type but lacks exploit, patch, or evidence of active exploitation.

    00000695
    58.0K followersView on X

Explore more