CVE-2026-82627
Received Received - Intake

PHP Object Injection in Uncanny Automator WordPress Plugin

Vulnerability report for CVE-2026-82627, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Wordfence

Description

The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
uncannyowl Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP Object Injection flaw in the Uncanny Automator WordPress plugin. It allows authenticated attackers with Subscriber-level access or higher to inject malicious PHP objects via deserialization of untrusted input. The attack requires a third-party integration plugin (like PeepSo, MailPoet, or WPForms) and a configured recipe storing attacker-controlled data as trigger meta.

Detection Guidance

Check for installed versions of the Uncanny Automator plugin up to 7.6.1.1. Review WordPress user roles for Subscriber-level access or higher. Inspect third-party integrations like PeepSo, MailPoet, or WPForms for configured recipes storing untrusted data.

Impact Analysis

An attacker could exploit this to delete arbitrary files on the server due to a POP chain within Uncanny Automator. This could lead to data loss, website downtime, or further compromise of the WordPress environment if combined with other vulnerabilities.

Compliance Impact

This vulnerability allows authenticated attackers with Subscriber-level access to delete arbitrary files on the server, which could lead to unauthorized data deletion or corruption. For GDPR, this could impact data integrity and availability, potentially violating Article 5 requirements for secure processing. For HIPAA, unauthorized file deletion could disrupt healthcare operations and compromise protected health information integrity.

Mitigation Strategies

Update the Uncanny Automator plugin to the latest version beyond 7.6.1.1. Remove or restrict Subscriber-level user access. Disable unused third-party integrations. Monitor for unauthorized file deletions or suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82627. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart