A Missing Authorization vulnerability, CVE-2026-15025, in the Uncanny Automator WordPress plugin versions up to and including 7.3.2, allows authenticated attackers with Subscriber-level access or higher to enumerate sensitive data from integrated Google Contacts and Mautic services, potentially consuming third-party API quotas.
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress
wordpress
uncanny-automator
missing-authorization
data-enumeration
web
1r
1t
1c