PT-2026-79505 · WordPress · Automatorwp

·

CVE-2026-76074

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AutomatorWP versions prior to 5.8.5
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated users with subscriber-level access or higher can retrieve the configured Campaign Monitor mailing list catalog, including all list IDs and names, which should be restricted to users with manager capabilities. This is possible via the automatorwp campaign monitor get lists AJAX action. The required nonce (a security token used to prevent cross-site request forgery) is emitted unconditionally on every WordPress admin page via wp localize script, allowing any subscriber visiting /wp-admin/profile.php to obtain it.
Recommendations Update to a version newer than 5.8.4.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76074

Affected Products

Automatorwp