PT-2026-56148 · WordPress · Uncanny Automator Pro
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
uncanny-automator-pro WordPress plugin versions prior to 7.3.0.6
Description
The software was distributed with malicious code following a compromise of the vendor's update and distribution infrastructure. This supply chain compromise introduced a backdoor that allows unauthenticated attackers to obtain an administrator session on affected sites. Additionally, the malicious code beacons the site's secret keys and administrator details to servers controlled by the attacker.
Recommendations
Update uncanny-automator-pro WordPress plugin to version 7.3.0.6 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uncanny Automator Pro