Uncanny Automator subscribers can query configured Google Contacts and Mautic integrations
Uncanny Automator through 7.3.2 omits capability and nonce checks from the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch and automator_mautic_render_contact_fields AJAX actions. Any authenticated Subscriber can invoke the corresponding ajax_fetch_labels(), segments_fetch(), tags_fetch() and render_contact_fields() handlers, causing administrator-configured integration credentials to retrieve Google Contacts groups or labels and Mautic segments, tags and contact-field definitions. This discloses integration metadata and can consume third-party API quota. The CNA record does not disclose additional action parameters.
- Component
- Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
- Plugin slug
uncanny-automator- Affected
- <= 7.3.2
- Safe version
7.4.0- Published
- Jul 28, 2026
- Weakness
- CWE-862 — Missing Authorization
This CVE was published Jul 28, 2026 and is one of 13 known issues for this plugin.
Update, patch or deactivate.
Update Uncanny Automator to 7.4.0 or later. Review Google Contacts and Mautic API logs and quota usage for unexpected requests from the affected WordPress site.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajax_fetch_labels, segments_fetch, tags_fetch, and render_contact_fields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Primary and upstream sources
- NVD record for CVE-2026-15025
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- Wordfence advisory wordfence.com