Impact
The vulnerability is a broken access control flaw in the AutomatorWP WordPress plugin, affecting all versions 5.8.3 and earlier. It allows an attacker to bypass normal permission checks and perform actions that a non‑privileged user should not be able to execute. This could expose sensitive user data or allow modification of automation flows, potentially leading to data tampering or privilege escalation within the site. The weakness is identified as CWE‑862, an improper authorization flaw.
Affected Systems
WordPress installations running the AutomatorWP plugin version 5.8.3 or older. The affected vendor is Ruben Garcia, the developer of AutomatorWP.
Risk and Exploitability
The CVSS score of 6.5 denotes a medium impact. No EPSS score is available, so a precise exploitation probability is unknown, but the flaw is actively listed on vulnerability databases such as Patchstack, indicating awareness among security communities. The vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is through the WordPress web interface, where an authenticated user with insufficient privileges could trigger the unauthorized action after exploiting the missing authorization checks.
OpenCVE Enrichment