Unauthorized Data Modification in AutomatorWP Plugin for WordPress
CVE-2025-9539

8HIGH

What is CVE-2025-9539?

The AutomatorWP plugin, designed for no-code automations and integrations in WordPress, is exposed to a serious vulnerability. This arises from a lack of capability checks on the automatorwp_ajax_import_automation_from_url function, affecting all versions up to and including 5.3.6. Authenticated users with Subscriber-level access and above can exploit this vulnerability to create arbitrary automations. The risk escalates significantly as these automations, once activated by administrators, can lead to unauthorized actions, including remote code execution and privilege escalation.

Affected Version(s)

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress * <= 5.3.6

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthew Rollings
.
CVE-2025-9539 : Unauthorized Data Modification in AutomatorWP Plugin for WordPress