Authorization Bypass Vulnerability in AutomatorWP Plugin for WordPress
CVE-2026-76074
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
What is CVE-2026-76074?
The AutomatorWP plugin for WordPress is susceptible to an authorization bypass flaw that affects all versions up to 5.8.4. This vulnerability allows authenticated users with minimal permissions, such as subscriber-level access, to retrieve restricted information from the site. Specifically, attackers can access the Campaign Monitor mailing list catalog, which includes sensitive list IDs and names, typically reserved for users with higher privileges. The underlying issue stems from improper verification of user permissions, compounded by an unprotected nonce that is publicly accessible on the WordPress admin pages. Thus, this vulnerability poses a significant risk, especially in environments where user access is not diligently controlled.
Affected Version(s)
AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress 0 <= 5.8.4