PT-2026-60435 · WordPress · Uncanny Automator
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin versions prior to 7.3.1.5
Description
Insufficient file path validation in the
fr token() function allows unauthenticated attackers to delete arbitrary files on the server. This can lead to remote code execution if critical files, such as wp-config.php, are removed. Exploitation occurs when a Forminator form is linked to an Uncanny Automator recipe configured for Everyone, enabling the submission of a malicious serialized payload. The process utilizes a gadget chain—a sequence of existing code fragments that can be leveraged for unintended execution—located within the Action Helpers Email destruct() method.Recommendations
Update the plugin to version 7.3.1.5 or later.
Fix
RCE
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uncanny Automator