Broken Authentication in AutomatorWP Plugin by AutomatorWP
CVE-2026-40785
7.1HIGH
What is CVE-2026-40785?
A vulnerability exists in the AutomatorWP plugin for WordPress, specifically in versions up to 5.6.7, where broken authentication could allow malicious actors unauthorized access to subscriber accounts. This flaw may lead to unauthorized actions being performed on behalf of legitimate users, making it crucial to apply security updates and mitigate risks associated with this vulnerability.
Affected Version(s)
AutomatorWP <= 5.6.7