CVE-2026-12375: Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
uncanny-automator-pro WordPress pluginto a version that resolves this vulnerability.Fixed in 7.3.0.6 - Operational
Assume the WordPress secret keys and administrator details exposed by the injected backdoor are compromised; rotate the site's secret keys and invalidate any exposed administrator sessions/credentials after updating the uncanny-automator-pro plugin to 7.3.0.6.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12375?
CVE-2026-12375 has a critical severity rating of 9.8.
How do I fix CVE-2026-12375?
To fix CVE-2026-12375, update the Uncanny Automator Pro WordPress plugin to version 7.3.0.6 or later.
What kind of attack does CVE-2026-12375 allow?
CVE-2026-12375 allows unauthenticated attackers to gain an administrator session through a backdoor.
Which version of the Uncanny Automator plugin is affected by CVE-2026-12375?
CVE-2026-12375 affects versions of the Uncanny Automator Pro WordPress plugin before 7.3.0.6.
What caused the vulnerability CVE-2026-12375?
CVE-2026-12375 was caused by a compromise of the vendor's update/distribution infrastructure, which led to the inclusion of malicious code.