Skip to main content
Vulnerability Database/CVE-2026-14281

CVE-2026-14281: WordPress WAWP Plugin Privilege Escalation

CVE-2026-14281 is a privilege escalation flaw in the WordPress WAWP plugin that lets unauthenticated attackers register as administrators. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-14281 Overview

CVE-2026-14281 is a privilege escalation vulnerability in the Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress. The flaw affects all versions up to and including 4.8.6. Unauthenticated attackers can register a new account with the administrator role through the publicly accessible REST endpoint POST /wp-json/wawp/v1/signup/<op>. The vulnerability stems from missing permission enforcement and the absence of a key allowlist in the finish_registration_logic function. A secondary flaw in the OTP (One-Time Password) handler makes the verification step trivially bypassable without inbox or SMS access.

Critical Impact

Unauthenticated attackers can gain full administrative access to vulnerable WordPress sites by abusing the signup REST route to inject wp_capabilities and wp_user_level meta keys.

Affected Products

  • Automation Web Platform – Notifications and OTP for WooCommerce plugin for WordPress
  • Advanced Country Code plugin for WordPress
  • All versions up to and including 4.8.6

Discovery Timeline

  • 2026-09-25 - CVE-2026-14281 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2026-14281

Vulnerability Analysis

The vulnerability is a classic Improper Privilege Management flaw [CWE-269] in the plugin's REST API surface. The finish_registration_logic function copies the attacker-controlled wawp_custom_fields parameter directly into update_user_meta() without filtering keys. Because WordPress stores role data in user meta, writing wp_capabilities with the value administrator and wp_user_level with 10 promotes the newly created account to administrator.

The signup REST route POST /wp-json/wawp/v1/signup/<op> is reachable without authentication and lacks a permission_callback that would restrict access. Attackers only need HTTP access to the target site to trigger the full account takeover primitive.

Root Cause

Two compounding defects create the exploit chain. First, the signup endpoint exposes user meta writes without an allowlist of permitted keys. Second, when OTP verification is enabled, the OTP session token (otp_transient) is returned in plaintext in the HTTP response body. The handle_magic_link_request() handler then marks that token as verified on any unauthenticated GET request containing it, never checking the OTP code value itself.

Attack Vector

An attacker sends a crafted POST request to the signup route containing a wawp_custom_fields payload with wp_capabilities and wp_user_level entries. If OTP is enforced, the attacker extracts the returned otp_transient from the response body and issues a GET request against the magic link handler to mark the session verified. The signup completes with administrator privileges granted to the attacker-controlled account.

The vulnerability manifests in the signup and OTP service classes. See the Wordfence Vulnerability Report and the referenced WordPress Signup Class source for technical details.

Detection Methods for CVE-2026-14281

Indicators of Compromise

  • Unexpected administrator accounts in wp_users with recent user_registered timestamps.
  • HTTP access logs showing POST requests to /wp-json/wawp/v1/signup/ paths from unauthenticated sources.
  • GET requests containing an otp_transient token parameter to the magic link handler.
  • Entries in wp_usermeta where wp_capabilities or wp_user_level were updated outside of normal admin workflows.

Detection Strategies

  • Alert on any REST request path matching /wp-json/wawp/v1/signup/ where the request body contains wp_capabilities or wp_user_level strings.
  • Correlate new WordPress user creation events with inbound REST traffic to the vulnerable endpoint.
  • Review web server access logs for repeated unauthenticated POSTs to the signup route, followed shortly by GETs that include an otp_transient parameter.

Monitoring Recommendations

  • Enable WordPress audit logging for user creation and role change events.
  • Forward web server and PHP error logs to a centralized analytics platform for long-term retention.
  • Baseline normal signup volume and alert on anomalous spikes in REST signup activity.

How to Mitigate CVE-2026-14281

Immediate Actions Required

  • Deactivate and remove the Automation Web Platform plugin from any WordPress site running version 4.8.6 or earlier until a patched release is confirmed installed.
  • Audit all WordPress administrator accounts and remove any that were not provisioned by legitimate administrators.
  • Rotate credentials, secret keys, and session tokens for any site that exposed the vulnerable endpoint.

Patch Information

Review the plugin Changeset Info and the Wordfence Vulnerability Report for the current remediation status. Update the plugin to a fixed release once published by the vendor.

Workarounds

  • Block external access to the /wp-json/wawp/v1/signup/ REST route at the web application firewall or reverse proxy layer.
  • Restrict REST API access to authenticated users where feasible using a permission_callback enforcement plugin.
  • Disable new user registration site-wide under WordPress Settings until the plugin is patched or removed.
bash
# Example nginx rule to block the vulnerable REST route
location ~* ^/wp-json/wawp/v1/signup/ {
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.