CVE-2026-82627: Uncanny Automator Vulnerability
TL;DR - CVE-2026-82627 affects Uncanny Automator through version 7.6.1.1. - The WordPress PHP object injection issue requires authenticated access, a compatible integration, and a vulnerable recipe configuration. - The documented impact is arbitrary file deletion through a property-oriented programming (POP) chain. - Upgrade to the latest release and investigate suspicious file deletions or recipe activity.
What Is the Root Cause?
The root cause is unsafe deserialization of untrusted input. A configured automation recipe can write attacker-controlled data into trigger metadata. When the plugin later processes and deserializes that data, an authenticated attacker may be able to inject a PHP object rather than an expected scalar value or benign data structure.
In PHP applications, deserialization can invoke magic methods and object behaviors defined by application classes. If the available classes form a property-oriented programming chain, an attacker may manipulate object properties to cause an unintended operation. For this vulnerability, the documented chain can result in arbitrary file deletion on the server.
The exploitation path has several prerequisites:
- Uncanny Automator must be installed in an affected version.
- The attacker must possess a WordPress account with Subscriber-level access or higher.
- A compatible integration plugin must be installed. Examples named in the vulnerability description include PeepSo, MailPoet, and WPForms.
- A recipe must be configured to store attacker-controlled data as trigger metadata.
- The relevant recipe or trigger-processing path must deserialize the stored value.
The retrieved material does not prove that every installation using one of these integrations is exploitable. It also does not establish remote code execution. Defenders should scope the issue around the documented file-deletion impact unless a separate technical advisory provides evidence of additional consequences.
Organizations assessing exposure should also review their broader third-party risk from WordPress integrations that pass user-controlled values into automation workflows.
What Happened?
CVE-2026-82627 is a high-severity Uncanny Automator vulnerability involving PHP object injection in the WordPress plugin. The vulnerable condition involves deserializing attacker-controlled trigger metadata. Exploitation requires more than simply installing the plugin: an attacker needs an authenticated WordPress account with Subscriber-level access or higher, a compatible third-party integration, and a recipe configured to store attacker-controlled data as trigger metadata.
The documented impact is arbitrary file deletion. Uncanny Automator contains a usable property-oriented programming (POP) chain that can be reached after object injection. The available vulnerability description does not establish unauthenticated exploitation, arbitrary PHP code execution, privilege escalation, or data exfiltration.
| Field | Assessment |
|---|---|
| CVE | CVE-2026-82627 |
| CVSS v3 base score | 7.5, High |
| CVSS vector | Not exposed in the retrieved NVD record; confirm directly in NVD before publication or automated scoring |
| Attack vector | Requires authenticated interaction with affected WordPress functionality; the exact CVSS vector is unconfirmed |
| Authentication | Subscriber-level access or higher |
| Affected versions | All versions through and including 7.6.1.1 |
| Patch status | A later release is available, but the exact security-fixed version requires vendor confirmation |
| Current public product version | 7.7.0, released September 30, 2026, according to the WordPress.org product page |
| CISA KEV status | Not listed |
Administrators should treat the issue as relevant wherever Uncanny Automator is installed alongside integrations such as PeepSo, MailPoet, or WPForms. A Subscriber account alone does not prove exposure. It does, however, make a review of recipes, integrations, and account activity more urgent.
Analyst’s Take: Prioritize version inventory and recipe review on sites that combine Uncanny Automator with the named integrations and permit Subscriber-level accounts. The lack of a CISA KEV listing or verified public proof of concept lowers the evidence for active exploitation, but it does not remove the need to investigate suspicious file deletions.
Who Needs to Act?
The affected product is the Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin. All versions up to and including 7.6.1.1 are identified as affected. This includes installations using the free plugin package if they meet the authentication, integration, and recipe prerequisites.
The WordPress.org plugin page showed version 7.7.0, dated 2026-09-30, at the time of assessment. The retrieved sources do not explicitly state that 7.7.0 is the security-fixed version. The NVD record references WordPress plugin changeset 3721435, but the changeset could not be independently retrieved because the request returned HTTP 403.
Therefore, 7.7.0 is the operational upgrade target. Administrators should verify the release notes, changelog, or vendor advisory before treating it as a definitively confirmed fix.
Organizations should prioritize sites where Uncanny Automator is combined with PeepSo, MailPoet, WPForms, or other plugins that feed user-controlled values into automation recipes. Sites that permit public registration or have numerous Subscriber accounts deserve additional scrutiny because the vulnerability does not require an Administrator role.
Why Is the CVSS Score High?
The recorded CVSS v3 base score is 7.5, classified as High. The score indicates meaningful security impact and should prompt remediation, while the exploitation prerequisites reduce its reach compared with an unauthenticated, internet-wide vulnerability.
The exact CVSS vector string was not exposed in the retrieved NVD record. The individual components, including attack vector, attack complexity, privileges required, user interaction, scope, and confidentiality, integrity, and availability impacts, therefore cannot be stated reliably. The Subscriber-level requirement is one reason not to guess the privileges-required component from the base score alone.
The known impact is arbitrary file deletion through a POP chain. That can disrupt WordPress operation, remove plugins or themes, damage content, or assist a broader compromise if an attacker can delete security controls or application files. The available record does not establish code execution, so a claim that the CVSS score reflects remote code execution would be unsupported.
Has CVE-2026-82627 Been Exploited?
CVE-2026-82627 is not listed in the CISA Known Exploited Vulnerabilities catalog based on the assessment performed on 2026-10-08. There is no CISA KEV date added, due date, required action, or ransomware campaign flag for this CVE. The lookup provides no CISA KEV confirmation of active exploitation in the wild.
The absence of a KEV listing is not proof that exploitation has never occurred. It means only that the CVE was not present in the catalog lookup. The retrieved authoritative material does not establish confirmed in-the-wild exploitation, and no ransomware association was reported.
No verified, CVE-specific public proof-of-concept repository or exploit was identified in the searches performed for this assessment. The Wordfence entry referenced by NVD is vulnerability intelligence, not evidence of a public exploit.
| Question | Status |
|---|---|
| Confirmed active exploitation | Not established |
| CISA KEV listing | No |
| Verified public proof of concept | Not identified |
| Exploitability | Possible when all documented prerequisites exist |
How Do I Know If My Site Is Affected?
Start by inventorying every WordPress site running Uncanny Automator and recording the installed version. Versions through 7.6.1.1 should be treated as affected. Then identify whether PeepSo, MailPoet, WPForms, or another integration is installed and whether any recipe stores user-controlled data as trigger metadata.
Review WordPress audit logs, web-server logs, PHP logs, and filesystem monitoring data for activity involving recipe execution, trigger processing, and the affected integrations. Pay particular attention to activity performed by Subscriber-level accounts, unexpected account creation, unusual logins, and file deletions occurring shortly after requests to WordPress endpoints.
A generic web-server search can identify likely investigation candidates, although endpoint names vary by plugin version and site configuration:
# Search access logs for affected integration names and common WordPress execution paths
grep -Ei 'uncanny|automator|peepso|mailpoet|wpforms|admin-ajax\\.php|wp-json' \\
/var/log/nginx/access.log /var/log/apache2/access.log
# Look for recent PHP, plugin, theme, upload, and configuration file deletions
find /var/www/html -type f -mtime -14 \\
\( -path '*/wp-content/plugins/*' -o -path '*/wp-content/themes/*' \\
-o -path '*/wp-content/uploads/*' -o -name 'wp-config.php' \) -print
A useful SIEM starting point is to alert when a low-privilege WordPress account performs an automation-related request followed by filesystem deletion or a missing plugin file:
event.dataset:webserver
AND (
url.path:*admin-ajax.php* OR
url.path:*wp-json* OR
message:*automator* OR
message:*uncanny*
)
AND user.role:(Subscriber OR subscriber)
This query is intentionally broad. It is a hunting pattern, not a confirmed exploit signature. Correlate file deletion events, PHP-FPM errors, and WordPress audit records by timestamp, source IP, user ID, and request ID where available.
What Should I Do About CVE-2026-82627?
Upgrade Uncanny Automator to the latest vendor-published release. The public WordPress.org page showed 7.7.0, while the latest affected version is 7.6.1.1. Because the retrieved patch changeset and vendor security statement could not be independently verified, confirm that 7.7.0 contains the fix through the vendor changelog or support channel.
For a WP-CLI-managed installation, use:
# Review the installed version
wp plugin get uncanny-automator --field=version
# Update to the latest WordPress.org release
wp plugin update uncanny-automator
# Confirm the resulting version
wp plugin get uncanny-automator --field=version
Test the update against representative recipes and integrations before broad deployment. If the site is managed through a hosting panel or WordPress administrative interface, use the platform’s normal plugin update mechanism and retain a backup before changing production files.
If immediate upgrading is not possible, deactivate the plugin and disable affected integrations where operationally feasible:
# Emergency containment when WP-CLI is available
wp plugin deactivate uncanny-automator
Deactivation is preferable to leaving a known vulnerable plugin active, but it may interrupt business-critical automations. If the plugin must remain enabled temporarily:
- Restrict Subscriber account creation.
- Review existing Subscriber accounts.
- Remove unnecessary accounts.
- Prevent untrusted users from reaching affected recipe workflows.
- Review integrations that pass user-controlled data into trigger metadata.
Role restrictions alone are not a complete fix.
After containment or upgrade, review automation recipes and trigger metadata for serialized or object-like values that were not expected by the application. Audit WordPress core, plugins, themes, uploads, configuration files, scheduled tasks, and administrator accounts for unauthorized changes. Investigate any unexplained deletion rather than restoring files without determining how they were removed.
As part of broader access-control remediation, organizations may also review how privileged WordPress credentials are stored and shared. A dedicated password manager such as Try 1Password → can help teams enforce unique credentials and reduce the risk of reused administrator passwords, although it does not remediate this plugin vulnerability.
Where Did This Information Come From?
The primary references available for this assessment are listed below. The WordPress repository changeset is the most relevant patch reference, but it returned HTTP 403 during retrieval, so the exact code change and fixed version could not be confirmed from that source.
| Reference | Purpose |
|---|---|
| NVD CVE record for CVE-2026-82627 | CVE description, severity, and vulnerability metadata |
| WordPress plugin changeset 3721435 | Primary repository patch reference |
| Wordfence vulnerability intelligence entry | Vulnerability intelligence reference cited by NVD |
| Uncanny Automator on WordPress.org | Product page, releases, and public changelog |
| CISA Known Exploited Vulnerabilities Catalog | Exploitation-in-the-wild catalog status |
The available evidence supports a high-confidence assessment of the CVE identifier, product, affected range through 7.6.1.1, authentication requirement, integration prerequisites, POP-chain behavior, arbitrary file deletion impact, CVSS score, and non-KEV status.
The exact CVSS vector, definitive fixed version, detailed patch implementation, public proof-of-concept status, and confirmed exploitation history remain unconfirmed in the retrieved material. Upgrade to the latest release first, verify the fix directly, and investigate site telemetry rather than relying on the absence of KEV or public exploit reporting.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.