CVE-2026-82627: Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included <= 7.6.1.1 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion

Published Oct 8, 2026
·
Updated

The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.

Affected Software

1 affected component
Uncanny Automator Uncanny Automator<=7.6.1.1

Event History

Oct 8, 2026
CVE Published
via MITRE·01:26 AM
Data Sourced
via MITRE·01:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which WordPress sites are exposed to exploitation?

Exposure requires Uncanny Automator version 7.6.1.1 or earlier, an installed third-party integration plugin such as PeepSo, MailPoet, or WPForms, and a configured recipe that stores attacker-controlled data as trigger metadata. Sites without that integration-and-recipe condition are not described as exploitable by this issue.

2

What access does an attacker need?

The attacker must be authenticated with at least Subscriber-level WordPress access. No user interaction is required, but exploitation has high attack complexity because the required integration and recipe conditions must be present.

3

What can be done while patching is delayed?

Restrict or remove Subscriber-level accounts that are not required, since Subscriber access is sufficient. Review configured Uncanny Automator recipes and the relevant third-party integrations, particularly recipes that store user-controlled trigger data; disabling affected functionality can reduce exposure until an update is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203