External risk intelligence

WordPress Automation Web Platform Plugin Privilege Escalation and OTP Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-14281

The vulnerability exists in a WordPress plugin that implements public-facing registration and OTP features. These services are intentionally exposed to the internet to allow user sign-ups and account management, making the vulnerable REST API endpoints directly accessible to unauthenticated remote attackers in any standard deployment.

Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security issue has been identified in a WordPress plugin, affecting its user registration and authentication processes. This vulnerability could allow unauthenticated individuals to gain administrative access to websites using the plugin, potentially compromising site integrity and data. The primary concern is to determine if our environment utilizes this specific plugin and, if so, to what extent.

  • Allows unauthorized admin access.
  • Critical for all WordPress site owners.
  • Confirm plugin use and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by interacting with a publicly accessible REST API endpoint. By sending a specially crafted request to the `signup` endpoint, an attacker can bypass One-Time Password (OTP) verification and directly assign administrative privileges to a newly created user account. This allows them to gain complete control over the WordPress site.

  • Entry condition: No authentication needed.
  • Trigger point: Public signup REST API.
  • Resulting risk: Full administrative access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain administrative access to a WordPress site. The system's user registration process, including OTP verification, has flaws that an attacker could exploit to create an administrator account without proper authentication. This could lead to a complete compromise of the website and its data.

  • Website administrative control.
  • Unauthenticated registration bypass.
  • Full site compromise and data theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WordPress plugin "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" is likely managed by the website's owner or a designated web administrator. The first practical step is to identify all WordPress sites using this plugin, determine if their registration or OTP features are externally accessible, and then locate the specific site owner or administrator responsible for that instance. Remediation planning should prioritize critical or externally facing sites.

  • Site owners/administrators should own the issue.
  • Verify external accessibility of registration/OTP.
  • Plan remediation based on risk and exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Automation Web Platform plugin for WordPress?

This plugin is an extension for WooCommerce sites that adds functionality for user notifications, one-time password (OTP) authentication flows, and managing advanced country codes during checkout or account registration.

What is the CVE-2026-14281 weakness class?

This vulnerability is classified as CWE-269: Improper Privilege Management. It occurs because the plugin fails to check if a user is authorized to assign roles, allowing an attacker to modify internal account settings and grant themselves administrator privileges.

How does an attacker trigger this vulnerability?

An attacker targets the plugin's public REST API route used for user registration. By sending a request with malicious parameters, they can overwrite site user metadata. The attack does not require any existing account, nor does it require a valid OTP, as the verification logic can be bypassed entirely.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin, your site is likely at risk. Halo Surface Signal notes that because the affected features—like registration and OTP verification—are designed to be public-facing, the vulnerable REST endpoints are directly reachable by anyone on the internet, requiring no special network access.

What should I do if I run this software?

Immediately audit your WordPress installations to identify any active instances of the Automation Web Platform plugin. Confirm which sites utilize the affected registration or OTP features, and verify if those services are accessible to the public, as these represent the primary entry points for this threat.

References