PHP Object Injection Vulnerability in Uncanny Automator Plugin for WordPress
CVE-2026-82627

7.5HIGH

What is CVE-2026-82627?

The Uncanny Automator plugin for WordPress is susceptible to PHP Object Injection, affecting all versions up to 7.6.1.1. This vulnerability arises from the deserialization of untrusted input, enabling authenticated users with Subscriber-level access or greater to inject malicious PHP objects. This exploitation is particularly feasible when third-party integration plugins (like PeepSo, MailPoet, WPForms) are active and configurations that store attacker-controlled data as trigger metadata are implemented. Additionally, the presence of a chain of objects allows attackers to execute file deletion commands on the server, presenting a significant risk to site integrity.

Affected Version(s)

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included 0 <= 7.6.1.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3
.