Authorization Bypass in AutomatorWP Plugin for WordPress
CVE-2026-104728

4.3MEDIUM

What is CVE-2026-104728?

The AutomatorWP plugin, designed for no-code workflow automation and integration on WordPress, is susceptible to an authorization bypass vulnerability. This issue affects all versions up to and including 5.8.4 and stems from inadequate verification of user permissions. As a result, authenticated attackers, possessing subscriber-level access or higher, may exploit this flaw to gain unauthorized visibility into all records in the Fluent Forms database, including sensitive form IDs and titles. Proper security measures should be considered to mitigate risks associated with this vulnerability.

Affected Version(s)

AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI 0 <= 5.8.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.