7.5
CVE-2026-82627
- EPSS 0.27%
- Veröffentlicht 08.10.2026 01:26:38
- Zuletzt bearbeitet 08.10.2026 02:16:54
- Erkennungen
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included <= 7.6.1.1 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included <= 7.6.1.1 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion
The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.
Mögliche Gegenmaßnahme
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included: Update to version 7.7.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleruncannyowl
≫
Produkt
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included
Default Statusunaffected
Version <=
7.6.1.1
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included
Version
*-7.6.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.169 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://www.wordfence.com/threat-intel/vulnerabilities/id/ce918263-dc4a-4db1-a506-a9e6c8125741?source=cve
https://plugins.trac.wordpress.org/changeset/3721435/
https://www.wordfence.com/threat-intel/vulnerabilities/id/ce918263-dc4a-4db1-a506-a9e6c8125741