Vulnerabilities in WordPress Plugins
Multiple critical vulnerabilities have been identified in WordPress plugins that could allow unauthenticated malicious actors to obtain administrative privileges, delete files from the media library, or access and manipulate reservation-related information.
Affected Products
- Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code, versions up to and including 4.8.6.
- Customer Reviews for WooCommerce, versions up to and including 5.120.0.
- Online Scheduling and Appointment Booking System – Bookly, versions up to and including 28.2.
Impact
The vulnerabilities have been identified as:
- CVE-2026-14281: with a score of 9.8 in CVSS v3.1. There is a privilege escalation vulnerability. A malicious actor could register a new account with the administrator role and gain full access to the site, even if OTP is enabled.
- CVE-2026-89055: with a score of 9.1 in CVSS v3.1. There is an incorrect authorization issue. A malicious actor could delete arbitrary attachments from the Media Library, including administrator images and documents.
- CVE-2026-93399: with a score of 9.1 in CVSS v3.1. There is an insecure direct object reference issue. A malicious actor could enumerate order IDs, obtain tokens associated with other users' reservations, query calendar and appointment information, and permanently delete reservations that have not yet been completed.
Recommendation
- Update to the most recent version of the affected plugins to correct these vulnerabilities.
- Implement additional security measures, such as two-factor authentication and real-time monitoring.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-14281
- https://nvd.nist.gov/vuln/detail/CVE-2026-89055
- https://nvd.nist.gov/vuln/detail/CVE-2026-93399
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.