Cross Site Scripting Vulnerability in AutomatorWP Plugin by Patchstack
CVE-2026-42650
7.2HIGH
What is CVE-2026-42650?
The AutomatorWP plugin for WordPress versions up to 5.6.7 contains an unauthenticated Cross Site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages viewed by other users. Successful exploitation of this vulnerability can lead to unauthorized data access and manipulation, impacting the security of users interacting with the affected plugin.
Affected Version(s)
AutomatorWP <= 5.6.7