CVE-2026-42650: WordPress AutomatorWP plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability
Published Jun 15, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
Affected Software
1 affected component
wordpress/automatorwp<=5.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AutomatorWP pluginto a version that resolves this vulnerability.Fixed in 5.6.8
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42650?
The severity of CVE-2026-42650 is rated high with a score of 7.2.
2
How do I fix CVE-2026-42650?
To fix CVE-2026-42650, update the AutomatorWP plugin to version 5.6.8 or later.
3
What type of vulnerability is CVE-2026-42650?
CVE-2026-42650 is an unauthenticated Cross Site Scripting (XSS) vulnerability.
4
What versions of AutomatorWP are affected by CVE-2026-42650?
CVE-2026-42650 affects AutomatorWP versions 5.6.7 and earlier.
5
Is user authentication required to exploit CVE-2026-42650?
No, CVE-2026-42650 can be exploited without user authentication.