Unauthorized Data Modification in AutomatorWP Plugin for WordPress
CVE-2025-9539
8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-9539?
The AutomatorWP plugin, designed for no-code automations and integrations in WordPress, is exposed to a serious vulnerability. This arises from a lack of capability checks on the automatorwp_ajax_import_automation_from_url
function, affecting all versions up to and including 5.3.6. Authenticated users with Subscriber-level access and above can exploit this vulnerability to create arbitrary automations. The risk escalates significantly as these automations, once activated by administrators, can lead to unauthorized actions, including remote code execution and privilege escalation.
Affected Version(s)
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress * <= 5.3.6