Skip to content
HighVulnerability

CVE-2026-82627: Uncanny Automator WordPress plugin PHP object injection via deserialization

Identifier
CVE-2026-82627
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

CVE-2026-82627 affects The Uncanny Automator AI + Automation plugin for WordPress in all versions up to and including 7.6.1.1. The flaw is PHP Object Injection via deserialization of untrusted input, which lets an authenticated user with Subscriber-level access or higher inject a PHP object when a third-party integration plugin such as PeepSo, MailPoet or WPForms is installed and a recipe stores attacker-controlled data as trigger meta. A POP chain within Uncanny Automator allows the attacker to delete arbitrary files on the server.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.