Description
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Published: 2026-08-24
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw in the AutomatorWP WordPress plugin, affecting all versions 5.8.3 and earlier. It allows an attacker to bypass normal permission checks and perform actions that a non‑privileged user should not be able to execute. This could expose sensitive user data or allow modification of automation flows, potentially leading to data tampering or privilege escalation within the site. The weakness is identified as CWE‑862, an improper authorization flaw.

Affected Systems

WordPress installations running the AutomatorWP plugin version 5.8.3 or older. The affected vendor is Ruben Garcia, the developer of AutomatorWP.

Risk and Exploitability

The CVSS score of 6.5 denotes a medium impact. No EPSS score is available, so a precise exploitation probability is unknown, but the flaw is actively listed on vulnerability databases such as Patchstack, indicating awareness among security communities. The vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is through the WordPress web interface, where an authenticated user with insufficient privileges could trigger the unauthorized action after exploiting the missing authorization checks.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Remediation

Vendor Solution

Update the WordPress AutomatorWP Plugin to the latest available version (at least 5.8.4).


OpenCVE Recommended Actions

  • Update the AutomatorWP plugin to version 5.8.4 or later, which removes the broken access control flaw.
  • If an immediate update is not possible, disable or uninstall the AutomatorWP plugin until a patch is applied, as the vulnerability relies on its functionality.
  • Review and tighten role or capability assignments in WordPress to ensure that users only have the minimum privileges required.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Title WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T21:31:33.520Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T22:17:20.540

Modified: 2026-08-24T22:17:20.540

Link: CVE-2026-78266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses