Unauthorized Data Modification in AutomatorWP Plugin for WordPress
CVE-2025-9539
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-9539?
The AutomatorWP plugin, designed for no-code automations and integrations in WordPress, is exposed to a serious vulnerability. This arises from a lack of capability checks on the automatorwp_ajax_import_automation_from_url function, affecting all versions up to and including 5.3.6. Authenticated users with Subscriber-level access and above can exploit this vulnerability to create arbitrary automations. The risk escalates significantly as these automations, once activated by administrators, can lead to unauthorized actions, including remote code execution and privilege escalation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress * <= 5.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved