CVE-2026-14281 is an unauthenticated privilege-escalation vulnerability affecting Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code for WordPress through version 4.8.6. A publicly accessible signup REST handler does not enforce permissions, and its registration logic passes attacker-controlled custom-field data to WordPress user-metadata updates without restricting which metadata keys may be set. An attacker can assign role-related metadata during registration and create an account with the WordPress administrator role. Where signup OTP verification is enabled, the plugin exposes the OTP session token in the registration response and accepts that token in an unauthenticated magic-link verification request without validating the OTP value, allowing the OTP control to be bypassed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains one interactive Python 3 program, CVE-2026-14281.py, and a README. It is a standalone tool rather than a Metasploit, Nuclei, or other framework module. The Langz class normalizes supplied targets, disables TLS-certificate warnings and verification, and uses a shared requests session with a browser-like User-Agent. Its mass-scan mode concurrently POSTs a probe to the WAWP signup REST endpoint, prints status results, and writes URLs classified as vulnerable to an output file. Classification is heuristic: a JSON response containing "wawp" or "wawp/v1" is sufficient for the mass scanner to label a host VULNERABLE, so mass-scan output indicates endpoint exposure rather than definitive exploitation. The documented single-target workflow targets a claimed improper privilege-management issue in 101gen's Automation Web Platform WordPress plugin through version 4.8.6. It attempts unauthenticated account creation with attacker-supplied wp_capabilities and wp_user_level metadata, uses the purportedly disclosed OTP transient to verify the account, and logs in as the resulting administrator. Visible cleanup logic accesses wp-admin user-management pages, extracts a deletion nonce when available, and deletes the created account. This gives the tool administrative control of a successfully exploited WordPress instance, with downstream capabilities such as user/plugin/theme/content management and potential RCE through normal administrator functionality. The exploit is operational/basic: it automates a hardcoded privilege-escalation payload and cleanup flow, but does not provide a modular or user-selectable payload framework.
This six-file repository is a standalone Python 3 proof-of-concept/exploitation utility for CVE-2026-14281 in the Automation Web Platform (WAWP) WordPress plugin. Its only code file, poc.py, uses requests and urllib3 to normalize target URLs, fingerprint publicly accessible plugin files, parse detected versions, assess WordPress/WAWP REST availability, and execute either single-target or threaded list-based scans. It targets versions at or below 4.8.6. The core issue is an unauthenticated public signup handler that accepts wawp_custom_fields and ultimately writes arbitrary WordPress user metadata without an allowlist. The exploit injects wp_capabilities and wp_user_level metadata to register an administrator-capable account. It supports operator-selected credentials, optional serialized capability data, optional wp-admin verification, HTTP proxying, configurable timeouts/concurrency, JSONL output, and candidate/credential hit lists. README.md documents the issue and usage; requirements.txt lists requests and urllib3; targets.example.txt supplies sample base URLs. The script distinguishes patched, absent-plugin, REST-reachable, OTP-blocked, and live-probe-confirmed cases. OTP-enabled signup can prevent completion of the one-request account-registration chain, so this is not guaranteed to bypass OTP.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated privilege-escalation vulnerability in the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code WordPress plugin through version 4.8.6. A publicly accessible signup REST endpoint permits attacker-controlled user-meta fields, allowing assignment of administrator capability metadata. Its signup OTP protection can be bypassed because a plaintext session token is returned and can be marked verified without OTP-code validation.
Critical unauthenticated privilege-escalation vulnerability in the WordPress Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin. Missing authorization on a public REST signup route and unrestricted attacker-controlled user-meta updates permit creation of administrator accounts. Its OTP signup verification can be bypassed because an OTP session token is exposed in the HTTP response and accepted as verified without validating the OTP code.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.