Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: Code execution
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 7.3.1.4.
- Component
- Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
- Plugin slug
uncanny-automator- Affected
- <= 7.3.1.4
- Safe version
> 7.3.1.4- Published
- Jul 16, 2026
This CVE was published Jul 16, 2026 and is one of 12 known issues for this plugin.
Patch or disable the affected component.
Update Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin to a release after 7.3.1.4, or disable and remove it until a fixed version is available.
Technical description
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires a Forminator form connected to an Uncanny Automator recipe configured for 'Everyone', allowing unauthenticated form submissions to supply the malicious serialized payload; a gadget chain is present within the plugin via the Action_Helpers_Email __destruct() method, meaning no external gadget library is required.
CVE / CNA vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Primary and upstream sources
- NVD record for CVE-2026-15008
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- Wordfence advisory wordfence.com