CVE-2026-14281 | 101gen Automation Web Platform Plugin up to 4.8.6 on WordPress Signup /wp-json/wawp/v1/signup/ wawp_custom_fields privileges management

SecurityVulns

A vulnerability was found in 101gen Automation Web Platform Plugin up to 4.8.6 on WordPress. It has been declared as critical. This issue affects the function finish_registration_logic/handle_magic_link_request of the file /wp-json/wawp/v1/signup/ of the component Signup. The manipulation of the argument wawp_custom_fields results in improper privilege management.

This vulnerability is reported as CVE-2026-14281. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More