Authorization Bypass Vulnerability in AutomatorWP Plugin for WordPress
CVE-2026-76074

4.3MEDIUM

What is CVE-2026-76074?

The AutomatorWP plugin for WordPress is susceptible to an authorization bypass flaw that affects all versions up to 5.8.4. This vulnerability allows authenticated users with minimal permissions, such as subscriber-level access, to retrieve restricted information from the site. Specifically, attackers can access the Campaign Monitor mailing list catalog, which includes sensitive list IDs and names, typically reserved for users with higher privileges. The underlying issue stems from improper verification of user permissions, compounded by an unprotected nonce that is publicly accessible on the WordPress admin pages. Thus, this vulnerability poses a significant risk, especially in environments where user access is not diligently controlled.

Affected Version(s)

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress 0 <= 5.8.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.