CVE-2026-15008: Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the frtoken function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires a Forminator form connected to an Uncanny Automator recipe configured for 'Everyone', allowing unauthenticated form submissions to supply the malicious serialized payload; a gadget chain is present within the plugin via the ActionHelpersEmail destruct() method, meaning no external gadget library is required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin (WordPress)to a version that resolves this vulnerability.Fixed in 7.3.1.4 - Compensating control
Restrict the Forminator form and its connection to the Uncanny Automator recipe so the recipe is not configured for 'Everyone'; prevent unauthenticated users from submitting the Forminator form to supply the malicious serialized payload.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15008?
CVE-2026-15008 has a severity rating of high, classified as 8.1 on the CVSS scale.
How do I fix CVE-2026-15008?
To fix CVE-2026-15008, update the Uncanny Automator plugin to version 7.3.1.5 or higher, which resolves the file path validation issue.
What type of vulnerability is CVE-2026-15008?
CVE-2026-15008 is an unauthenticated PHP object injection vulnerability that allows for arbitrary file deletion.
Which application is affected by CVE-2026-15008?
CVE-2026-15008 affects the Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress.
When was CVE-2026-15008 published?
CVE-2026-15008 was published on July 16, 2026.