{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/notifications-and-otp-for-woocommerce-advanced-country-code/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-77264"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Notifications and OTP for WooCommerce, Advanced Country Code"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["The Automation"],"content_html":"\u003cp\u003eThe 'Notifications and OTP for WooCommerce, Advanced Country Code' plugin for WordPress, in versions up to and including 4.8.6, contains a critical authentication bypass vulnerability (CVE-2026-77264). The flaw resides in the handle_email_otp_return() function, which incorrectly exposes the secret magic login token within the HTTP response of an OTP request rather than restricting it to the user's email address. This oversight allows unauthenticated attackers to retrieve valid login tokens for any known email address associated with the site. By capturing this token, an attacker can authenticate as any user, including site administrators, resulting in full unauthorized access to the affected WordPress environment. Defenders should prioritize updating to the latest secure version of this plugin immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for complete site takeover by an unauthenticated attacker. Successful exploitation provides administrative access, enabling the attacker to modify site content, inject malicious scripts, manipulate e-commerce data, or exfiltrate sensitive user information. Given the nature of WordPress plugins, this affects any organization utilizing this plugin for WooCommerce notifications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Notifications and OTP for WooCommerce, Advanced Country Code' plugin to a version beyond 4.8.6 immediately to address CVE-2026-77264.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for repeated requests to the handle_email_otp_return() endpoint that return successful 200 responses to non-standard or unexpected IP addresses.\u003c/li\u003e\n\u003cli\u003eAudit administrative user activity for account creations or password resets occurring from unauthorized locations immediately following the detection of large-scale OTP requests.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-21T09:23:11Z","date_published":"2026-08-21T09:23:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-77264/","summary":"The Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to an authentication bypass via secret token leakage in the handle_email_otp_return function.","title":"Authentication Bypass in WordPress Notifications and OTP Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-77264/"}],"language":"en","title":"CraftedSignal Threat Feed - Notifications and OTP for WooCommerce, Advanced Country Code","version":"https://jsonfeed.org/version/1.1"}