PHP Object Injection Vulnerability in Uncanny Automator Plugin for WordPress
CVE-2026-82627
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-82627?
The Uncanny Automator plugin for WordPress is susceptible to PHP Object Injection, affecting all versions up to 7.6.1.1. This vulnerability arises from the deserialization of untrusted input, enabling authenticated users with Subscriber-level access or greater to inject malicious PHP objects. This exploitation is particularly feasible when third-party integration plugins (like PeepSo, MailPoet, WPForms) are active and configurations that store attacker-controlled data as trigger metadata are implemented. Additionally, the presence of a chain of objects allows attackers to execute file deletion commands on the server, presenting a significant risk to site integrity.
Affected Version(s)
Uncanny Automator β AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included 0 <= 7.6.1.1