{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3auncanny_owluncanny_automator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:uncanny_owl:uncanny_automator:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82627"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Uncanny Automator (\u003c= 7.6.1.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","cve-2026-82627"],"_cs_type":"advisory","_cs_vendors":["Uncanny Owl"],"content_html":"\u003cp\u003eUncanny Automator, a WordPress plugin designed for automation, contains a critical PHP Object Injection vulnerability tracked as CVE-2026-82627. The flaw affects all versions up to and including 7.6.1.1. It arises from the insecure deserialization of untrusted input processed during the execution of automation recipes.\u003c/p\u003e\n\u003cp\u003eAn attacker requires authenticated access with at least Subscriber-level privileges to initiate the exploit. The attack is contingent upon the presence of specific third-party integration plugins, such as PeepSo, MailPoet, or WPForms, and requires the target to have an automation recipe configured that stores user-controlled data as trigger meta. Leveraging a property-oriented programming (POP) chain present within the plugin codebase, an attacker can bypass standard security controls to delete arbitrary files on the underlying web server, potentially leading to a complete service disruption or further compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users with low-level privileges (Subscriber) to delete critical system or application files on the WordPress server. This could lead to a site going offline, the removal of configuration files, or the destruction of essential plugin data. This vulnerability affects any WordPress environment using the Uncanny Automator plugin combined with supported third-party integrations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Uncanny Automator plugin to the version released after 7.6.1.1 that contains the patch for CVE-2026-82627.\u003c/li\u003e\n\u003cli\u003eAudit user permissions for WordPress subscribers to ensure that only trusted users have access to features interacting with third-party integration automation recipes.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) on the web server to detect unexpected file deletion activity originating from the web application process (e.g., www-data, apache).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T02:48:17Z","date_published":"2026-10-08T02:48:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-uncanny-automator-php-injection/","summary":"Authenticated attackers can exploit a PHP Object Injection vulnerability in Uncanny Automator versions 7.6.1.1 and earlier to achieve arbitrary file deletion via a POP chain.","title":"PHP Object Injection in Uncanny Automator WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-uncanny-automator-php-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:uncanny_owl:uncanny_automator:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}