Skip to content
Threat Feed
high advisory

PHP Object Injection in Uncanny Automator WordPress Plugin

Authenticated attackers can exploit a PHP Object Injection vulnerability in Uncanny Automator versions 7.6.1.1 and earlier to achieve arbitrary file deletion via a POP chain.

CVE search metadata

CVE search record: CVE-2026-82627. Severity: high. CVSS: 7.5. KEV: no. Product: Uncanny Automator (<= 7.6.1.1). Brief: PHP Object Injection in Uncanny Automator WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-uncanny-automator-php-injection/

Uncanny Automator, a WordPress plugin designed for automation, contains a critical PHP Object Injection vulnerability tracked as CVE-2026-82627. The flaw affects all versions up to and including 7.6.1.1. It arises from the insecure deserialization of untrusted input processed during the execution of automation recipes.

An attacker requires authenticated access with at least Subscriber-level privileges to initiate the exploit. The attack is contingent upon the presence of specific third-party integration plugins, such as PeepSo, MailPoet, or WPForms, and requires the target to have an automation recipe configured that stores user-controlled data as trigger meta. Leveraging a property-oriented programming (POP) chain present within the plugin codebase, an attacker can bypass standard security controls to delete arbitrary files on the underlying web server, potentially leading to a complete service disruption or further compromise.

Impact

Successful exploitation allows authenticated users with low-level privileges (Subscriber) to delete critical system or application files on the WordPress server. This could lead to a site going offline, the removal of configuration files, or the destruction of essential plugin data. This vulnerability affects any WordPress environment using the Uncanny Automator plugin combined with supported third-party integrations.

Recommendation

  1. Upgrade the Uncanny Automator plugin to the version released after 7.6.1.1 that contains the patch for CVE-2026-82627.
  2. Audit user permissions for WordPress subscribers to ensure that only trusted users have access to features interacting with third-party integration automation recipes.
  3. Implement file integrity monitoring (FIM) on the web server to detect unexpected file deletion activity originating from the web application process (e.g., www-data, apache).

Immediate actions

Upgrade Uncanny Automator to the latest patched version

IT Operations 48h

Mitigations

Upgrade Uncanny Automator to patched version

immediate IT Operations

CVE-2026-82627