HighVulnerability
CVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-82627
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
CVE-2026-82627 affects The Uncanny Automator AI + Automation plugin for WordPress in all versions up to and including 7.6.1.1. The flaw is PHP Object Injection via deserialization of untrusted input, which lets an authenticated user with Subscriber-level access or higher inject a PHP object when a third-party integration plugin such as PeepSo, MailPoet or WPForms is installed and a recipe stores attacker-controlled data as trigger meta. A POP chain within Uncanny Automator allows the attacker to delete arbitrary files on the server.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database