CVE-2026-78266: WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability
Published Aug 24, 2026
·Updated
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Affected Software
1 affected component
AutomatorWP<=5.8.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AutomatorWP pluginto a version that resolves this vulnerability.Fixed in 5.8.4
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as subscriber broken access control, and the vector requires low privileges. An attacker would need an authenticated account with Subscriber-level access.
2
What is the likely security impact?
The supplied CVSS vector indicates high integrity impact, with no confidentiality or availability impact. Exploitation could allow unauthorized modification of affected functionality or data.