Junglewise Threat Intelligence

CVE-2026-39699: massiveshift AI Workflow Automation missing authorization

CVE-2026-39699 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

A vulnerability exists in the AI Workflow Automation plugin for WordPress, which is used to automate business processes using artificial intelligence. Due to incorrect access controls, an unauthorized person could potentially perform actions or modify settings that should be restricted to administrators. This could lead to unauthorized changes in how the AI workflows operate on the website.

Technical details

The AI Workflow Automation (ai-workflow-automation-lite) plugin for WordPress suffers from a missing authorization (CWE-862) vulnerability. The flaw is rooted in incorrectly configured access control security levels, which fails to properly validate the privileges of a user before allowing them to execute specific functions. An unauthenticated attacker can exploit this over the network without any user interaction to perform unauthorized actions, though the impact is limited to integrity (data modification) rather than data theft or service disruption. While NVD lists the affected versions as <= 1.4.2, the primary source (Patchstack) indicates the vulnerability persists through version 2.0.3 and is fixed in version 2.0.4.

Affected products

  • massiveshift AI Workflow Automation (ai-workflow-automation-lite) <= 1.4.2 (NVD); <= 2.0.3 (Patchstack)

Timeline

  • 2026-01-28: other: Reported by Nabil Irawan
  • 2026-02-27: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published to NVD
  • 2026-02-27: patched: Fixed in version 2.0.4

References