Authentication Bypass in WordPress Notifications and OTP Plugin
The Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to an authentication bypass via secret token leakage in the handle_email_otp_return function.
CVE search metadata
CVE search record: CVE-2026-77264. Severity: critical. CVSS: 9.8. KEV: no. Product: Notifications and OTP for WooCommerce, Advanced Country Code. Brief: Authentication Bypass in WordPress Notifications and OTP Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-08-cve-2026-77264/
The 'Notifications and OTP for WooCommerce, Advanced Country Code' plugin for WordPress, in versions up to and including 4.8.6, contains a critical authentication bypass vulnerability (CVE-2026-77264). The flaw resides in the handle_email_otp_return() function, which incorrectly exposes the secret magic login token within the HTTP response of an OTP request rather than restricting it to the user's email address. This oversight allows unauthenticated attackers to retrieve valid login tokens for any known email address associated with the site. By capturing this token, an attacker can authenticate as any user, including site administrators, resulting in full unauthorized access to the affected WordPress environment. Defenders should prioritize updating to the latest secure version of this plugin immediately.
Impact
The vulnerability allows for complete site takeover by an unauthenticated attacker. Successful exploitation provides administrative access, enabling the attacker to modify site content, inject malicious scripts, manipulate e-commerce data, or exfiltrate sensitive user information. Given the nature of WordPress plugins, this affects any organization utilizing this plugin for WooCommerce notifications.
Recommendation
- Update the 'Notifications and OTP for WooCommerce, Advanced Country Code' plugin to a version beyond 4.8.6 immediately to address CVE-2026-77264.
- Review web server access logs for repeated requests to the handle_email_otp_return() endpoint that return successful 200 responses to non-standard or unexpected IP addresses.
- Audit administrative user activity for account creations or password resets occurring from unauthorized locations immediately following the detection of large-scale OTP requests.
Immediate actions
Update WordPress plugin to version > 4.8.6