PT-2026-60435 · WordPress · Uncanny Automator

·

CVE-2026-15008

·

Published

2026-07-15

·

Updated

2026-07-16

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin versions prior to 7.3.1.5
Description Insufficient file path validation in the fr token() function allows unauthenticated attackers to delete arbitrary files on the server. This can lead to remote code execution if critical files, such as wp-config.php, are removed. Exploitation occurs when a Forminator form is linked to an Uncanny Automator recipe configured for Everyone, enabling the submission of a malicious serialized payload. The process utilizes a gadget chain—a sequence of existing code fragments that can be leveraged for unintended execution—located within the Action Helpers Email destruct() method.
Recommendations Update the plugin to version 7.3.1.5 or later.

Fix

RCE

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15008

Affected Products

Uncanny Automator