Description
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Uncanny Automator Pro WordPress plugin distributed before version 7.3.0.6. This vulnerability is a CWE‑284 improper access control flaw. When the vendor’s update infrastructure was compromised, malicious code was injected into the plugin package. The injected backdoor grants an attacker without authentication a fully privileged administrator session and then transmits the site’s secret keys and administrator details to external servers. Because the attacker gains direct administrative credentials, the impact is a complete compromise of the affected WordPress site.

Affected Systems

WordPress installations that have the Uncanny Automator Pro plugin version 7.3.0.5 or earlier are susceptible. Any site or applied an update before 7.3.0.6 during the period when the vendor’s update server was compromised could have received the malicious distribution.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as critical, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is directly triggered by normal plugin installation or update, requiring no additional conditions. The likely attack vector is compromised software distribution, where the attacker subverts the vendor’s update server to deliver malicious code.

Generated by OpenCVE AI on July 25, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Uncanny Automator Pro to version 7.3.0.6 or later, which removes the injected backdoor.
  • Verify that all plugin files match the official, trusted source—checking checksums or source code integrity before re‑installing.
  • Audit installed WordPress, and delete any files that were not part of the original distribution.
  • After updating, reset all WordPress administrator passwords and regenerate the site secret keys to invalidate any credentials that may have been exfiltrated.
  • Maintain regular, verified backups and adhere to if a compromise occurs.

Generated by OpenCVE AI on July 25, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 16 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 12 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 11 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 09 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
Title Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-07T13:15:21.512Z

Reserved: 2026-06-16T07:48:21.773Z

Link: CVE-2026-12375

cve-icon Vulnrichment

Updated: 2026-07-07T13:14:47.468Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:00:14Z

Weaknesses

No weakness.