Impact
The vulnerability resides in the Uncanny Automator Pro WordPress plugin distributed before version 7.3.0.6. This vulnerability is a CWE‑284 improper access control flaw. When the vendor’s update infrastructure was compromised, malicious code was injected into the plugin package. The injected backdoor grants an attacker without authentication a fully privileged administrator session and then transmits the site’s secret keys and administrator details to external servers. Because the attacker gains direct administrative credentials, the impact is a complete compromise of the affected WordPress site.
Affected Systems
WordPress installations that have the Uncanny Automator Pro plugin version 7.3.0.5 or earlier are susceptible. Any site or applied an update before 7.3.0.6 during the period when the vendor’s update server was compromised could have received the malicious distribution.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is directly triggered by normal plugin installation or update, requiring no additional conditions. The likely attack vector is compromised software distribution, where the attacker subverts the vendor’s update server to deliver malicious code.
OpenCVE Enrichment