Impact
AutomatorWP plugin versions up to 5.7.2 contain an unauthenticated cross‑site scripting vulnerability (CWE‑79) that allows external actors to inject malicious JavaScript. The injected script is executed in the browsers of users who view the compromised content, creating a risk of XSS. No other impact such as privilege escalation is described in the CVE.
Affected Systems
The flaw affects WordPress sites that have installed the AutomatorWP plugin from any version 5.7.2 or older, published by Ruben Garcia. Any site running those versions without updating is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests low likelihood of current exploitation, and the flaw is not listed in the CISA KEV catalog, implying no widely known public exploits. Because the vulnerability is unauthenticated, an attacker only needs to supply a crafted payload through the plugin’s input fields; the payload will then be rendered for authenticated users who view the affected content.
OpenCVE Enrichment