Skip to content
Brief Security & Trust ·

Uncanny Automator WordPress plugin has a flaw that can delete server files

NIST lists CVE-2026-82627, rated high severity, in all versions up to 7.6.1.1.

In brief
  • NIST lists a high-severity flaw (CVE-2026-82627) in the Uncanny Automator plugin for WordPress. It affects every version up to and including 7.6.1.1.
  • Attack needs a logged-in account, a third-party integration plugin and a specific recipe setup. It can let an attacker delete files on the server.

NIST's National Vulnerability Database published a record on 8 October 2026 for CVE-2026-82627. It covers the Uncanny Automator plugin for WordPress, which adds AI and automation tools. NIST says every version up to and including 7.6.1.1 is affected. The flaw is a PHP Object Injection: the plugin rebuilds objects from data it should not trust. NIST says an attacker with a Subscriber account or higher could use it. A chain of code inside the plugin then lets the attacker delete any file on the server.

NIST lists conditions for the attack. A third-party integration plugin must be installed, such as PeepSo, MailPoet or WPForms. A recipe, which is an automation rule in Uncanny Automator, must also store data the attacker controls. Wordfence ([email protected]) gave the flaw a CVSS 3.1 score of 7.5, rated high. The record does not say whether anyone has used the flaw in attacks. It does not name a fixed version. It links to a code change on the WordPress plugin site and a Wordfence entry, but does not say what the change does.

Anyone who runs WordPress sites with this plugin should check which version they have. Sites that also use an integration plugin and recipes that save user-supplied data fit the conditions NIST describes. Subscriber accounts are often easy to create, so the account requirement is a low bar on sites that allow sign-ups.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: NIST NVD.