Executive brief
AutomatorWP is a WordPress plugin used to automate tasks between different WordPress plugins and services. A security flaw in versions 5.6.7 and earlier allows users with low-level 'Subscriber' accounts to bypass authentication mechanisms. This could allow an attacker to perform unauthorized actions or potentially gain administrative control over the website, leading to full site compromise or data loss.
Technical details
AutomatorWP versions up to and including 5.6.7 are vulnerable to an authentication bypass (CWE-288) via an alternate path. The vulnerability allows an authenticated user with low-level 'Subscriber' privileges to bypass intended authentication checks. By exploiting this flaw, a remote attacker can execute actions typically reserved for higher-privileged users, which may lead to privilege escalation or full administrative access to the WordPress site. The issue is resolved in version 5.6.8.
Affected products
- AutomatorWP AutomatorWP <= 5.6.7
Timeline
- 2026-03-17: other: Reported by Jakub Herman
- 2026-04-23: advisory: Initial Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date