SecAlerts
A

AutomatorWP

Security Risk Profile

27
/100
low

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 1, 2021 to present

10
Total CVEs
5
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
27/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
4
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
Code Injection
1
2
SQL Injection
1
3
XSS
1
4
CSRF
1

Most Affected Products

1. AutomatorWP AutomatorWP3
2. AutomatorWP AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress2
3. AutomatorWP Automator2
4. AutomatorWP AutomatorWP WordPress2
5. AutomatorWP Automator plugin1

Recent Vulnerabilities

See more →
CVE-2026-104728
CVSS 4.3medium

AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via wp_ajax_automatorwp_fluentform_get_forms AJAX Action

Oct 10, 2026🔧 No Patch
CVE-2026-76074
CVSS 4.3medium

AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX Action

Aug 22, 2026🔧 No Patch
CVE-2026-76057
CVSS 4.3medium

AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_convertkit_get_forms AJAX Action

Aug 22, 2026🔧 No Patch
CVE-2026-40785
CVSS 7.1high

WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability

Jun 15, 2026🔧 No Patch
CVE-2025-9539
CVSS 8.0EPSS 0%high

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation

Sep 9, 2025🔧 No Patch
CVE-2025-9542
CVSS 5.4EPSS 0%medium

AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions

Sep 9, 2025🔧 No Patch
CVE-2025-5487
CVSS 7.2EPSS 0%high

AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions

Jun 14, 2025🔧 No Patch
CVE-2024-12626
CVSS 9.6critical

AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value

Dec 19, 2024🔧 No Patch
CVE-2023-23992
CVSS 5.4medium

WordPress AutomatorWP Plugin <= 2.5.0 is vulnerable to Cross Site Request Forgery (CSRF)

Feb 28, 2023
CVE-2021-24717
CVSS 8.8high

AutomatorWP < 1.7.6 - Missing Authorization and Privilege Escalation

Nov 1, 2021🔧 No Patch

Monitor AutomatorWP in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

AutomatorWP Security Vulnerabilities & Risk Score | 10 CVEs | SecAlerts - SecAlerts