CVE-2026-14281: Privilege Escalation in Automation Web Platform for WordPress
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation due to missing permission enforcement on a publicly accessible REST route and the absence of a key allowlist in the `finish_registration_logic` function. This allows unauthenticated attackers to register a new account with the administrator role and gain full administrative access to the site. The vulnerability has a CVSS score of 9.8 and is considered CRITICAL.