Multiple critical vulnerabilities have been identified in WordPress plugins that could allow unauthenticated malicious actors to obtain administrative privileges, delete files from the media library, or access and manipulate reservation-related information.
Affected Products
- Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code, versions up to and including 4.8.6.
- Customer Reviews for WooCommerce, versions up to and including 5.120.0.
- Online Scheduling and Appointment Booking System – Bookly, versions up to and including 28.2.
Impact
The vulnerabilities have been identified as:
- CVE-2026-14281: with a score of 9.8 in CVSS v3.1. There is a privilege escalation vulnerability. A malicious actor could register a new account with the administrator role and gain full access to the site, even if OTP is enabled.
- CVE-2026-89055: with a score of 9.1 in CVSS v3.1. There is an incorrect authorization issue. A malicious actor could delete arbitrary attachments from the Media Library, including administrator images and documents.
- CVE-2026-93399: with a score of 9.1 in CVSS v3.1. There is an insecure direct object reference issue. A malicious actor could enumerate order IDs, obtain tokens associated with other users' reservations, query calendar and appointment information, and permanently delete reservations that have not yet been completed.
Recommendation
- Update to the most recent version of the affected plugins to correct these vulnerabilities.
- Implement additional security measures, such as two-factor authentication and real-time monitoring.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-14281
- https://nvd.nist.gov/vuln/detail/CVE-2026-89055
- https://nvd.nist.gov/vuln/detail/CVE-2026-93399
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
