Impact
The vulnerability involves a malicious backdoor that was injected into the Uncanny Automator Pro WordPress plugin before version 7.3.0.6. The backdoor permits attackers to obtain an administrator session without any authenticated credentials and then exfiltrate the site’s secret keys and administrator details to attacker‑controlled servers. Because the injected code effectively bypasses all access controls, the impact is a full compromise of the affected WordPress installation, allowing an attacker to read, modify, delete, or add content and to persist by masking the compromise as legitimate.
Affected Systems
WordPress sites that installed the Uncanny Automator Pro plugin version 7.3.0.5 or earlier during the period when the vendor’s update infrastructure was compromised are at risk. Any site that applied a plugin update before 7.3.0.6 while the distribution server was compromised could have received a malicious package and thus be vulnerable.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical. The EPSS score of less than 1% suggests that exploitation is not widely observed yet, but the presence of an unauthenticated administrative bypass means that a successful attack would have immediate, catastrophic effects. Attackers can exploit the flaw simply by installing or updating the plugin; no additional authentication or complex conditions are required. The likely attack vector is a compromised software distribution pipeline, where an attacker delivers a malicious plugin package to unsuspecting site owners.
OpenCVE Enrichment