CVE-2025-9542: AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify integration settings or view existing automations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9542?
The severity of CVE-2025-9542 is considered high due to unauthorized access and potential data modification.
How does CVE-2025-9542 affect systems using the AutomatorWP plugin?
CVE-2025-9542 allows unauthorized users to access and modify data within the AutomatorWP plugin due to a lack of capability checks.
How do I fix CVE-2025-9542?
To fix CVE-2025-9542, update the AutomatorWP plugin to the latest version that includes the necessary capability checks.
Which versions of AutomatorWP are impacted by CVE-2025-9542?
All versions of the AutomatorWP plugin up to and including version 5.3.7 are impacted by CVE-2025-9542.
What types of data are at risk due to CVE-2025-9542?
CVE-2025-9542 puts various data handled by the AutomatorWP plugin at risk, including user data and settings, due to unauthorized access.