CVE-2026-40785: WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability
Published Jun 15, 2026
·Updated
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
Affected Software
1 affected component
AutomatorWP AutomatorWP<=5.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AutomatorWP Pluginto a version that resolves this vulnerability.Fixed in 5.6.8
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40785?
The severity of CVE-2026-40785 is rated as high, with a score of 7.1.
2
What type of vulnerability is CVE-2026-40785?
CVE-2026-40785 is a Broken Authentication vulnerability in the AutomatorWP plugin.
3
How does CVE-2026-40785 affect WordPress sites?
CVE-2026-40785 allows unauthorized access through broken authentication for subscribers in AutomatorWP versions 5.6.7 and below.
4
How do I fix CVE-2026-40785?
To fix CVE-2026-40785, update the AutomatorWP plugin to the latest version immediately.
5
Is CVE-2026-40785 exploitable remotely?
Yes, CVE-2026-40785 is exploitable remotely due to its authentication weaknesses.