« Back to list

Automatorwp

Automatorwp: vulnerabilities and CVEs

Automatorwp has 11 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months5
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76074Medium (4.3)0.40%—Aug 22, 2026
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due…
CVE-2026-76057Medium (4.3)0.44%—Aug 22, 2026
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due…
CVE-2026-42775High (7.1)0.25%—Jun 15, 2026
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.
CVE-2026-42650High (7.2)0.28%—Jun 15, 2026
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
CVE-2025-68561High (7.6)0.27%—Dec 23, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4.
CVE-2025-9539High (8)0.46%—Sep 9, 2025
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the…
CVE-2025-5487High (7.2)0.40%—Jun 14, 2025
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions…
CVE-2025-48280High (7.6)0.34%—May 19, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows Blind SQL Injection.This issue affects AutomatorWP: from n/a through <=…
CVE-2024-12626Critical (9.6)0.74%—Dec 19, 2024
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter…
CVE-2023-23992Medium (4.3)0.26%—Feb 28, 2023
Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete.
CVE-2021-24717High (8.8)1.3%—Nov 1, 2021
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System3
  2. T1059.007 JavaScript3
  3. T1210 Exploitation of Remote Services3
  4. T1189 Drive-by Compromise2
  5. T1059 Command and Scripting Interpreter1
  6. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.