NIST's National Vulnerability Database published a record on 8 October 2026 for CVE-2026-82627. It covers the Uncanny Automator plugin for WordPress, which adds AI and automation tools. NIST says every version up to and including 7.6.1.1 is affected. The flaw is a PHP Object Injection: the plugin rebuilds objects from data it should not trust. NIST says an attacker with a Subscriber account or higher could use it. A chain of code inside the plugin then lets the attacker delete any file on the server.
NIST lists conditions for the attack. A third-party integration plugin must be installed, such as PeepSo, MailPoet or WPForms. A recipe, which is an automation rule in Uncanny Automator, must also store data the attacker controls. Wordfence ([email protected]) gave the flaw a CVSS 3.1 score of 7.5, rated high. The record does not say whether anyone has used the flaw in attacks. It does not name a fixed version. It links to a code change on the WordPress plugin site and a Wordfence entry, but does not say what the change does.
Anyone who runs WordPress sites with this plugin should check which version they have. Sites that also use an integration plugin and recipes that save user-supplied data fit the conditions NIST describes. Subscriber accounts are often easy to create, so the account requirement is a low bar on sites that allow sign-ups.