CVE · High

CVE-2026-15025 — Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.4.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15025 Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.4.0 Missing Authorization High 7.5 < 7.4.0 7.4.0 2026-07-27

CVE-2026-15025

The Uncanny Automator plugin for WordPress suffers from a critical security flaw in versions up to 7.3.2. Specifically, the plugin's handling of several AJAX actions is flawed due to inadequate permission checks and lack of nonce verification. This allows attackers with minimal privileges (Subscriber level or higher) to access sensitive data, including Google Contacts groups and labels, as well as Mautic segments and tags, via integration credentials set by administrators, also consuming third-party API quotas in the process.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.