CVE-2026-82627: Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included <= 7.6.1.1 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion
The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.
Affected Software
Event History
Frequently Asked Questions
Which WordPress sites are exposed to exploitation?
Exposure requires Uncanny Automator version 7.6.1.1 or earlier, an installed third-party integration plugin such as PeepSo, MailPoet, or WPForms, and a configured recipe that stores attacker-controlled data as trigger metadata. Sites without that integration-and-recipe condition are not described as exploitable by this issue.
What access does an attacker need?
The attacker must be authenticated with at least Subscriber-level WordPress access. No user interaction is required, but exploitation has high attack complexity because the required integration and recipe conditions must be present.
What can be done while patching is delayed?
Restrict or remove Subscriber-level accounts that are not required, since Subscriber access is sufficient. Review configured Uncanny Automator recipes and the relevant third-party integrations, particularly recipes that store user-controlled trigger data; disabling affected functionality can reduce exposure until an update is applied.