Junglewise Threat Intelligence

CVE-2026-42775: AutomatorWP unauthenticated XSS in WordPress plugin

CVE-2026-42775 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: AutomatorWP. Vendors: AutomatorWP.

Executive brief

AutomatorWP is a WordPress plugin used to automate tasks between different WordPress plugins and services. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of session cookies, or the display of fraudulent content to site visitors. This occurs when a site administrator or visitor interacts with a specially crafted link or page created by the attacker.

Technical details

AutomatorWP <= 5.7.2 is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated attacker can exploit this by sending a crafted request to a vulnerable site, which requires a victim (typically an administrator) to perform an action such as clicking a malicious link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 5.7.3.

Affected products

  • AutomatorWP AutomatorWP <= 5.7.2

Timeline

  • 2026-05-03: other: Vulnerability reported by researcher daroo
  • 2026-06-03: patched: Version 5.7.3 released and advisory published by Patchstack
  • 2026-06-15: advisory: NVD published CVE-2026-42775

References

Related threats