AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_convertkit_get_forms AJAX Action
medium
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...
- CVSS:
- 4.3
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.5
- Disclosed:
- Aug 21, 2026
CVE-2026-76057 on NVD →
AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX Action
medium
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...
- CVSS:
- 4.3
- Affected:
- up to 5.8.4
- Fixed in:
- 5.8.5
- Disclosed:
- Aug 21, 2026
CVE-2026-76074 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 - Unauthenticated Stored Cross-Site Scripting
high
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- CVSS:
- 7.2
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Jun 3, 2026
CVE-2026-42775 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Unauthenticated Stored Cross-Site Scripting
high
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- CVSS:
- 7.2
- Affected:
- up to 5.6.7
- Fixed in:
- 5.6.8
- Disclosed:
- Apr 29, 2026
CVE-2026-42650 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization
medium
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.6.7. This makes it possible for authenticated attackers, with Subscrib...
- CVSS:
- 4.3
- Affected:
- up to 5.6.7
- Fixed in:
- 5.6.8
- Disclosed:
- Apr 23, 2026
CVE-2026-40785 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] <= 5.2.4 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows SQL Injection.This issue affects AutomatorWP: from n/a through 5.2.4.
- Affected:
- up to 5.2.4
- Fix:
- No patched version reported
- Disclosed:
- Dec 23, 2025
CVE-2025-68561 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation
high
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up to, and including, 5.3.6. This...
- CVSS:
- 8
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.7
- Disclosed:
- Sep 8, 2025
CVE-2025-9539 on NVD →
AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions
medium
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible...
- CVSS:
- 5.4
- Affected:
- up to 5.3.7
- Fixed in:
- 5.3.8
- Disclosed:
- Sep 8, 2025
CVE-2025-9542 on NVD →
AutomatorWP <= 5.2.4 - Authenticated (Administrator+) SQL Injection
medium
The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and ab...
- CVSS:
- 4.9
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.5
- Disclosed:
- Jun 19, 2025
CVE-2025-68561 on NVD →
AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions
high
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of su...
- CVSS:
- 7.2
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Jun 13, 2025
CVE-2025-5487 on NVD →
AutomatorWP <= 5.2.1.3 - Authenticated (Administrator+) SQL Injection
medium
The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and...
- CVSS:
- 4.9
- Affected:
- up to 5.2.1.3
- Fixed in:
- 5.2.2
- Disclosed:
- May 19, 2025
CVE-2025-48280 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 5.2.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows Blind SQL Injection. This issue affects AutomatorWP: from n/a through 5.2.1.3.
- Affected:
- up to 5.2.2
- Fixed in:
- 5.2.2
- Disclosed:
- May 19, 2025
CVE-2025-48280 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 5.1.0
unknown
[en] The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output esc...
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.0
- Disclosed:
- Dec 19, 2024
CVE-2024-12626 on NVD →
AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value
critical
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping...
- CVSS:
- 9.6
- Affected:
- up to 5.0.9
- Fixed in:
- 5.1.0
- Disclosed:
- Dec 18, 2024
CVE-2024-12626 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 2.5.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete.
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Feb 28, 2023
CVE-2023-23992 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 2.5.9
unknown
Update the WordPress AutomatorWP plugin to the latest available version (at least 2.5.9).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress AutomatorWP Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their curr...
- Affected:
- up to 2.5.9
- Fixed in:
- 2.5.9
- Disclosed:
- Feb 15, 2023
AutomatorWP <= 2.5.8 - Cross Site Request Forgery via bulk_delete
medium
The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8. This is due to missing or incorrect nonce validation on the bulk_delete() function. This makes it possible for unauthenticated attackers to bulk delete CT objects via a forged request granted they c...
- CVSS:
- 4.3
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.9
- Disclosed:
- Feb 14, 2023
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 2.5.9
unknown
The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8. This is due to missing or incorrect nonce validation on the bulk_delete() function. This makes it possible for unauthenticated attackers to bulk delete CT objects via a forged request granted they c...
- Affected:
- up to 2.5.9
- Fixed in:
- 2.5.9
- Disclosed:
- Feb 14, 2023
AutomatorWP <= 2.5.0 - Cross Site Request Forgery
medium
The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. This is due to missing nonce validation on the delete() function. This makes it possible for unauthenticated attackers to delete display settings, granted they can trick a site administrator into pe...
- CVSS:
- 4.3
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Jan 20, 2023
CVE-2023-23992 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 1.7.6
unknown
[en] The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Nov 1, 2021
CVE-2021-24717 on NVD →
AutomatorWP <= 1.7.5 - Privilege Escalation
high
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
- CVSS:
- 8.8
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Sep 28, 2021
CVE-2021-24717 on NVD →
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] < 5.2.6
unknown
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.6
CVE-2025-5487 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database