plugin

Automatorwp Vulnerabilities

22 known security issues reported for the Automatorwp WordPress plugin. Most recent disclosed Aug 21, 2026.

1 critical 5 high 8 medium

Running Automatorwp on your site? Check whether your installed version is affected.

Scan your site free

AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_convertkit_get_forms AJAX Action

medium

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...

CVSS:
4.3
Affected:
up to 5.8.4
Fixed in:
5.8.5
Disclosed:
Aug 21, 2026

CVE-2026-76057 on NVD →

AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX Action

medium

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...

CVSS:
4.3
Affected:
up to 5.8.4
Fixed in:
5.8.5
Disclosed:
Aug 21, 2026

CVE-2026-76074 on NVD →

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 - Unauthenticated Stored Cross-Site Scripting

high

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

CVSS:
7.2
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Jun 3, 2026

CVE-2026-42775 on NVD →

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Unauthenticated Stored Cross-Site Scripting

high

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

CVSS:
7.2
Affected:
up to 5.6.7
Fixed in:
5.6.8
Disclosed:
Apr 29, 2026

CVE-2026-42650 on NVD →

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization

medium

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.6.7. This makes it possible for authenticated attackers, with Subscrib...

CVSS:
4.3
Affected:
up to 5.6.7
Fixed in:
5.6.8
Disclosed:
Apr 23, 2026

CVE-2026-40785 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] <= 5.2.4 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows SQL Injection.This issue affects AutomatorWP: from n/a through 5.2.4.

Affected:
up to 5.2.4
Fix:
No patched version reported
Disclosed:
Dec 23, 2025

CVE-2025-68561 on NVD →

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation

high

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up to, and including, 5.3.6. This...

CVSS:
8
Affected:
up to 5.3.6
Fixed in:
5.3.7
Disclosed:
Sep 8, 2025

CVE-2025-9539 on NVD →

AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions

medium

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible...

CVSS:
5.4
Affected:
up to 5.3.7
Fixed in:
5.3.8
Disclosed:
Sep 8, 2025

CVE-2025-9542 on NVD →

AutomatorWP <= 5.2.4 - Authenticated (Administrator+) SQL Injection

medium

The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and ab...

CVSS:
4.9
Affected:
up to 5.2.4
Fixed in:
5.2.5
Disclosed:
Jun 19, 2025

CVE-2025-68561 on NVD →

AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions

high

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of su...

CVSS:
7.2
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Jun 13, 2025

CVE-2025-5487 on NVD →

AutomatorWP <= 5.2.1.3 - Authenticated (Administrator+) SQL Injection

medium

The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and...

CVSS:
4.9
Affected:
up to 5.2.1.3
Fixed in:
5.2.2
Disclosed:
May 19, 2025

CVE-2025-48280 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 5.2.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows Blind SQL Injection. This issue affects AutomatorWP: from n/a through 5.2.1.3.

Affected:
up to 5.2.2
Fixed in:
5.2.2
Disclosed:
May 19, 2025

CVE-2025-48280 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 5.1.0

unknown

[en] The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output esc...

Affected:
up to 5.1.0
Fixed in:
5.1.0
Disclosed:
Dec 19, 2024

CVE-2024-12626 on NVD →

AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value

critical

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping...

CVSS:
9.6
Affected:
up to 5.0.9
Fixed in:
5.1.0
Disclosed:
Dec 18, 2024

CVE-2024-12626 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 2.5.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Feb 28, 2023

CVE-2023-23992 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 2.5.9

unknown

Update the WordPress AutomatorWP plugin to the latest available version (at least 2.5.9). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress AutomatorWP Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their curr...

Affected:
up to 2.5.9
Fixed in:
2.5.9
Disclosed:
Feb 15, 2023

AutomatorWP <= 2.5.8 - Cross Site Request Forgery via bulk_delete

medium

The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8. This is due to missing or incorrect nonce validation on the bulk_delete() function. This makes it possible for unauthenticated attackers to bulk delete CT objects via a forged request granted they c...

CVSS:
4.3
Affected:
up to 2.5.8
Fixed in:
2.5.9
Disclosed:
Feb 14, 2023

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 2.5.9

unknown

The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8. This is due to missing or incorrect nonce validation on the bulk_delete() function. This makes it possible for unauthenticated attackers to bulk delete CT objects via a forged request granted they c...

Affected:
up to 2.5.9
Fixed in:
2.5.9
Disclosed:
Feb 14, 2023

AutomatorWP <= 2.5.0 - Cross Site Request Forgery

medium

The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. This is due to missing nonce validation on the delete() function. This makes it possible for unauthenticated attackers to delete display settings, granted they can trick a site administrator into pe...

CVSS:
4.3
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jan 20, 2023

CVE-2023-23992 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 1.7.6

unknown

[en] The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Nov 1, 2021

CVE-2021-24717 on NVD →

AutomatorWP <= 1.7.5 - Privilege Escalation

high

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

CVSS:
8.8
Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Sep 28, 2021

CVE-2021-24717 on NVD →

AutomatorWP &#8211; Automator plugin for no-code automations, webhooks &amp; custom integrations in WordPress [automatorwp] < 5.2.6

unknown
Affected:
up to 5.2.6
Fixed in:
5.2.6

CVE-2025-5487 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database