Description
The AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate all Fluent Forms records, including form IDs and titles, from the fluentform_forms database table.
Published: 2026-10-10
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The AutomatorWP WordPress plugin has a missing authorization check that allows any authenticated user with subscriber or higher role to access an AJAX endpoint that returns database records from the Fluent Forms integration. An attacker can exploit this to list form IDs and titles, revealing internal application data and potentially aiding further reconnaissance or other attacks. The weakness is a classic authorization bypass (CWE‑862).

Affected Systems

WordPress sites running AutomatorWP version 5.8.4 or earlier, regardless of other installed plugins, are affected. The vulnerability originates in the ajax_functions.php file within the Fluent Forms integration of the plugin. Upgrading to AutomatorWP 6.0.3 or later removes the flaw.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a legitimate WordPress login with subscriber-level access and above; no special network exposure is needed aside from the normal site login interface. , the AJAX call can enumerate all forms, giving them a clear view of the site’s form architecture.

Generated by OpenCVE AI on October 10, 2026 at 09:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AutomatorWP to version 6.0.3 or later.
  • Restrict subscriber and lower role permissions to remove access to Form management features.
  • Monitor site logs for unauthorized AJAX requests to the automatorwp_fluentform_get_forms action.

Generated by OpenCVE AI on October 10, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate all Fluent Forms records, including form IDs and titles, from the fluentform_forms database table.
Title AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via wp_ajax_automatorwp_fluentform_get_forms AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:46.607Z

Reserved: 2026-10-02T11:47:04.862Z

Link: CVE-2026-104728

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:03.933

Modified: 2026-10-10T08:17:03.933

Link: CVE-2026-104728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses