Description
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Published: 2026-08-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access; Potential Data Compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a broken access control flaw in the AutomatorWP WordPress plugin, affecting all versions 5.8.3 and earlier. It allows an attacker to bypass normal permission checks and perform actions that a non‑privileged user should not be able to execute. This could expose sensitive user data or allow modification of automation flows, potentially leading to data tampering or privilege escalation within the site. The weakness is identified as CWE‑862, an improper authorization flaw.

Affected Systems

WordPress installations running the AutomatorWP plugin version 5.8.3 or older. The affected vendor is Ruben Garcia, the developer of AutomatorWP.

Risk and Exploitability

The CVSS score of 6.5 denotes a medium impact. No EPSS score is available, so a precise exploitation probability is unknown, but the flaw is actively listed on vulnerability databases such as Patchstack, indicating awareness among security communities. The vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is through the WordPress web interface, where an authenticated user with insufficient privileges could trigger the unauthorized action after exploiting the missing authorization checks.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Remediation

Vendor Solution

Update the WordPress AutomatorWP Plugin to the latest available version (at least 5.8.4).


OpenCVE Recommended Actions

  • Update the AutomatorWP plugin to version 5.8.4 or later, which removes the broken access control flaw.
  • If an immediate update is not possible, disable or uninstall the AutomatorWP plugin until a patch is applied, as the vulnerability relies on its functionality.
  • Review and tighten role or capability assignments in WordPress to ensure that users only have the minimum privileges required.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Ruben Garcia
Ruben Garcia automatorwp
Wordpress
Wordpress wordpress
Vendors & Products Ruben Garcia
Ruben Garcia automatorwp
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Title WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ruben Garcia Automatorwp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-25T19:02:39.587Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78266

cve-icon Vulnrichment

Updated: 2026-08-25T19:02:35.505Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T22:17:20.540

Modified: 2026-08-26T16:19:05.917

Link: CVE-2026-78266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:30:16Z

Weaknesses