Description
The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Arbitrary file deletion via PHP Object Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a PHP Object Injection flaw that allows an attacker who can log in as a subscriber or higher user on a WordPress site to inject malicious objects during a deserialization operation. The plugin processes data from third‑party integration plugins such as PeepSo, MailPoet, or WPForms, and stores attacker‑controlled trigger metadata. When a specially crafted object is deserialized the attacker can trigger a point‑of‑sale chain within the plugin that leads to arbitrary file deletion on the server, potentially compromising the entire hosting environment.

Affected Systems

WordPress sites running the Uncanny Automator – AI + Automation for WordPress plugin version 7.6.1.1 or earlier, especially those with any of the listed third‑party integrations installed and a recipe configured that saves user supplied trigger meta.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity flaw. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity may be low. Nonetheless, because the flaw requires only an authenticated subscriber‑level account, many sites are likely to have such users, and the effect of deleting arbitrary files can be exploited for further compromise or to disrupt services. The attack vector is authenticated but easily fulfilled in environments where subscription roles are broad and the plugin integration data is not properly sanitized.

Generated by OpenCVE AI on October 8, 2026 at 02:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest version of the Uncanny Automator plugin (>=7.6.2) to eliminate the deserialization vulnerability.
  • If immediate patching is not possible, remove or disable all third‑party integration plugins that supply trigger meta to the Uncanny Automator plugin and/or uninstall the plugin entirely.
  • Audit the user account list; revoke Subscriber or higher access from accounts that do not require it, and enforce least‑privilege on remaining accounts.

Generated by OpenCVE AI on October 8, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.
Title Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included <= 7.6.1.1 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-08T01:26:38.471Z

Reserved: 2026-08-30T09:51:57.933Z

Link: CVE-2026-82627

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T02:16:54.263

Modified: 2026-10-08T02:16:54.263

Link: CVE-2026-82627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T02:30:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data