Impact
The vulnerability is a PHP Object Injection flaw that allows an attacker who can log in as a subscriber or higher user on a WordPress site to inject malicious objects during a deserialization operation. The plugin processes data from third‑party integration plugins such as PeepSo, MailPoet, or WPForms, and stores attacker‑controlled trigger metadata. When a specially crafted object is deserialized the attacker can trigger a point‑of‑sale chain within the plugin that leads to arbitrary file deletion on the server, potentially compromising the entire hosting environment.
Affected Systems
WordPress sites running the Uncanny Automator – AI + Automation for WordPress plugin version 7.6.1.1 or earlier, especially those with any of the listed third‑party integrations installed and a recipe configured that saves user supplied trigger meta.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity flaw. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity may be low. Nonetheless, because the flaw requires only an authenticated subscriber‑level account, many sites are likely to have such users, and the effect of deleting arbitrary files can be exploited for further compromise or to disrupt services. The attack vector is authenticated but easily fulfilled in environments where subscription roles are broad and the plugin integration data is not properly sanitized.
OpenCVE Enrichment