Junglewise Threat Intelligence

CVE-2026-15025: Uncanny Automator WordPress plugin missing authorization in AJAX actions

CVE-2026-15025 · Severity: high · CVSS 7.5 · Published 2026-07-28

Technologies: Uncanny Owl Uncanny Automator. Vendors: Uncanny Owl.

Executive brief

Uncanny Automator is a WordPress plugin used to connect different apps and automate workflows. A security flaw allows logged-in users with basic permissions to access sensitive information from connected Google Contacts and Mautic accounts. This could lead to the exposure of private contact labels, tags, and marketing segments, as well as the depletion of third-party API usage limits.

Technical details

The Uncanny Automator plugin for WordPress is vulnerable to Missing Authorization in versions up to 7.3.2. The vulnerability exists within several AJAX actions, including automator_google_contacts_fetch_labels and automator_mautic_segment_fetch, because the corresponding handlers lack capability checks and nonce verification. An authenticated attacker with Subscriber-level access or higher can exploit this to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions. Additionally, an attacker can trigger these actions to consume the site's third-party API quotas. The issue is addressed in versions following 7.3.2.

Affected products

  • Uncanny Owl Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder up to, and including, 7.3.2

Timeline

  • 2026-07-28: advisory: NVD publication date

References

Related threats