The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Automation Web Platform – Notifications and OTP for WooCommerce plugin contains a critical authentication bypass vulnerability (CVSS 9.8) that exposes secret magic login tokens in plaintext API responses. Instead of securely delivering one-time passwords exclusively to registered email addresses, the vulnerable handle_email_otp_return() function returns the authentication token to any unauthenticated caller making a public OTP request. This allows attackers to intercept login credentials for any WordPress user account, including administrators, without needing existing access or credentials. WordPress sites using this plugin through version 4.8.6 are immediately at risk of complete account compromise and unauthorized administrative access.
While this CVE currently maps to zero Casky skills due to the specialized plugin context, practitioners using Casky's Claude-powered analysis would detect the underlying attack patterns by monitoring for CWE-640 (Weak Password Recovery Mechanism) violations and unusual authentication flows. Extended reasoning capabilities would flag suspicious indicators such as: repeated OTP requests to non-user-owned email addresses, successful logins immediately following OTP generation events, and API calls to notification endpoints returning sensitive tokens rather than confirmation-only responses. Security teams should prioritize identifying plugin installations through asset discovery, audit logs revealing OTP endpoint access patterns, and authentication event clustering that suggests token harvesting attempts—all detectable through behavioral analysis of access logs and API telemetry.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-77264. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation