Tag
high
advisory
CVE-2026-15025: Missing Authorization in Uncanny Automator WordPress Plugin
1 rule 1 TTP 1 CVEA Missing Authorization vulnerability, CVE-2026-15025, in the Uncanny Automator WordPress plugin versions up to and including 7.3.2, allows authenticated attackers with Subscriber-level access or higher to enumerate sensitive data from integrated Google Contacts and Mautic services, potentially consuming third-party API quotas.
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress
wordpress
uncanny-automator
missing-authorization
data-enumeration
web
1r
1t
1c
high
advisory
n8n Shared Credential Leakage via HTTP Request Pagination Vulnerability
5 TTPs 1 CVEAn authenticated n8n user with 'use-only editor access' can exploit CVE-2026-59209 in shared workflows when `N8N_EXPRESSION_ENGINE=vm` is enabled, allowing them to read sensitive HTTP Header Auth credentials from the `$request.headers` object within a paginated HTTP Request node's expression and exfiltrate them, bypassing credential domain restrictions.
n8n +2
vulnerability
credential-access
data-exfiltration
application-security
prototype-pollution
authentication-bypass
data-enumeration
5t
1c