Executive brief
Uncanny Automator, a popular WordPress plugin used to connect different apps and automate workflows, contains a security flaw that allows unauthorized individuals to delete files from the website's server. By deleting critical system files like the site's configuration file, an attacker can take complete control of the website or cause a total service outage. This vulnerability specifically affects sites using the Forminator plugin alongside certain Uncanny Automator configurations.
Technical details
The Uncanny Automator plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function. This flaw, combined with an insecure deserialization vulnerability (CWE-502), allows unauthenticated attackers to supply a malicious serialized payload via a Forminator form submission. The plugin contains a built-in gadget chain in the Action_Helpers_Email __destruct() method, which can be leveraged to delete arbitrary files on the server. Deleting critical files such as wp-config.php can lead to a full site takeover or remote code execution. The attack requires a specific configuration where a Forminator form is connected to an Uncanny Automator recipe set for 'Everyone'.
Affected products
- Uncanny Owl Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin up to, and including, 7.3.1.4
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
References
- https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/core/lib/recipe-parts/actions/trait-action-helpers-email.php
- https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/core/lib/utilities/db/class-automator-db-handler-triggers.php
- https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/core/services/email/attachment/handler.php
- https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/forminator/tokens/fr-tokens.php
- https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/forminator/triggers/anon-fr-submitform.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3607776%40uncanny-automator&new=3607776%40uncanny-automator
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9f2774e8-8b55-4c25-93c3-e0806208b1f3?source=cve