{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/uncanny-automator/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15025"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Uncanny Automator – Easy Automation, Integration, Webhooks \u0026 Workflow Builder plugin for WordPress"],"_cs_severities":["high"],"_cs_tags":["wordpress","uncanny-automator","missing-authorization","data-enumeration","web"],"_cs_type":"advisory","_cs_vendors":["Uncanny Automator"],"content_html":"\u003cp\u003eCVE-2026-15025 identifies a critical Missing Authorization vulnerability within the Uncanny Automator - Easy Automation, Integration, Webhooks \u0026amp; Workflow Builder plugin for WordPress, affecting all versions up to and including 7.3.2. This flaw stems from a lack of capability checks and nonce verification in several AJAX action handlers: \u003ccode\u003eautomator_google_contacts_fetch_labels\u003c/code\u003e, \u003ccode\u003eautomator_mautic_segment_fetch\u003c/code\u003e, \u003ccode\u003eautomator_mautic_tags_fetch\u003c/code\u003e, and \u003ccode\u003eautomator_mautic_render_contact_fields\u003c/code\u003e. Exploitation allows any authenticated attacker with Subscriber-level privileges or above to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions. This data is retrieved via administrator-configured integration credentials, and the successful execution of these actions can also lead to the consumption of third-party API quota. This vulnerability poses a risk of sensitive information disclosure and potential service disruption for organizations leveraging the plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to a WordPress instance, typically with Subscriber-level privileges or higher.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies a target WordPress site running the vulnerable Uncanny Automator plugin (versions up to 7.3.2).\u003c/li\u003e\n\u003cli\u003eUsing their authenticated session, the attacker sends a crafted HTTP POST request to the \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a vulnerable \u003ccode\u003eaction\u003c/code\u003e parameter, such as \u003ccode\u003eautomator_google_contacts_fetch_labels\u003c/code\u003e or \u003ccode\u003eautomator_mautic_segment_fetch\u003c/code\u003e, bypassing the intended authorization controls due to missing capability checks and nonce verification.\u003c/li\u003e\n\u003cli\u003eThe Uncanny Automator plugin processes the request as if it originated from an authorized user or context.\u003c/li\u003e\n\u003cli\u003eThe plugin utilizes the administrator-configured credentials for integrated services (Google Contacts or Mautic) to fetch data from the respective third-party APIs.\u003c/li\u003e\n\u003cli\u003eThe plugin returns sensitive information, such as Google Contacts groups/labels or Mautic segments, tags, and contact-field definitions, to the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully enumerates sensitive organizational data and potentially consumes the third-party API quota associated with the legitimate integration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15025 leads to the unauthorized enumeration of sensitive organizational data. This includes details like Google Contacts groups and labels, as well as Mautic segments, tags, and contact-field definitions. This information can reveal aspects of an organization's structure, customer base, or internal processes. Additionally, the attacker's repeated requests can cause unintended consumption of API quotas for integrated Google Contacts and Mautic services, potentially incurring unexpected costs or leading to service rate limits and disruptions for legitimate operations. The vulnerability affects any WordPress site using the Uncanny Automator plugin with affected versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-15025 immediately by updating the Uncanny Automator plugin to a version beyond 7.3.2.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-15025 Exploitation - Uncanny Automator Missing Authorization\u0026quot; to your SIEM to monitor for suspicious requests targeting the vulnerable AJAX actions.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any requests from low-privileged users to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e containing \u003ccode\u003eaction=automator_google_contacts_fetch_labels\u003c/code\u003e, \u003ccode\u003eaction=automator_mautic_segment_fetch\u003c/code\u003e, \u003ccode\u003eaction=automator_mautic_tags_fetch\u003c/code\u003e, or \u003ccode\u003eaction=automator_mautic_render_contact_fields\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T12:19:35Z","date_published":"2026-07-28T12:19:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-15025-uncanny-automator/","summary":"A Missing Authorization vulnerability, CVE-2026-15025, in the Uncanny Automator WordPress plugin versions up to and including 7.3.2, allows authenticated attackers with Subscriber-level access or higher to enumerate sensitive data from integrated Google Contacts and Mautic services, potentially consuming third-party API quotas.","title":"CVE-2026-15025: Missing Authorization in Uncanny Automator WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-15025-uncanny-automator/"}],"language":"en","title":"CraftedSignal Threat Feed - Uncanny-Automator","version":"https://jsonfeed.org/version/1.1"}