<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Uncanny Owl - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/uncanny-owl/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 02:48:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/uncanny-owl/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHP Object Injection in Uncanny Automator WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-uncanny-automator-php-injection/</link><pubDate>Thu, 08 Oct 2026 02:48:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-uncanny-automator-php-injection/</guid><description>Authenticated attackers can exploit a PHP Object Injection vulnerability in Uncanny Automator versions 7.6.1.1 and earlier to achieve arbitrary file deletion via a POP chain.</description><content:encoded><![CDATA[<p>Uncanny Automator, a WordPress plugin designed for automation, contains a critical PHP Object Injection vulnerability tracked as CVE-2026-82627. The flaw affects all versions up to and including 7.6.1.1. It arises from the insecure deserialization of untrusted input processed during the execution of automation recipes.</p>
<p>An attacker requires authenticated access with at least Subscriber-level privileges to initiate the exploit. The attack is contingent upon the presence of specific third-party integration plugins, such as PeepSo, MailPoet, or WPForms, and requires the target to have an automation recipe configured that stores user-controlled data as trigger meta. Leveraging a property-oriented programming (POP) chain present within the plugin codebase, an attacker can bypass standard security controls to delete arbitrary files on the underlying web server, potentially leading to a complete service disruption or further compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users with low-level privileges (Subscriber) to delete critical system or application files on the WordPress server. This could lead to a site going offline, the removal of configuration files, or the destruction of essential plugin data. This vulnerability affects any WordPress environment using the Uncanny Automator plugin combined with supported third-party integrations.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Uncanny Automator plugin to the version released after 7.6.1.1 that contains the patch for CVE-2026-82627.</li>
<li>Audit user permissions for WordPress subscribers to ensure that only trusted users have access to features interacting with third-party integration automation recipes.</li>
<li>Implement file integrity monitoring (FIM) on the web server to detect unexpected file deletion activity originating from the web application process (e.g., www-data, apache).</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>cve-2026-82627</category></item></channel></rss>