CVE-2026-15025: Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automatorgooglecontactsfetchlabels, automatormauticsegmentfetch, automatormautictagsfetch, and automatormauticrendercontactfields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajaxfetchlabels, segmentsfetch, tagsfetch, and rendercontactfields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15025?
The severity of CVE-2026-15025 is high, with a score of 7.5.
What does CVE-2026-15025 expose?
CVE-2026-15025 exposes sensitive integration metadata due to missing authorization in multiple AJAX endpoints.
How do I fix CVE-2026-15025?
To fix CVE-2026-15025, update the Uncanny Automator plugin to version 7.3.3 or later.
Which AJAX endpoints are affected by CVE-2026-15025?
The AJAX endpoints affected by CVE-2026-15025 include automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, and automator_mautic_tags_fetch.
Who is affected by CVE-2026-15025?
Users of the Uncanny Automator plugin for WordPress versions up to and including 7.3.2 are affected by CVE-2026-15025.