Junglewise Threat Intelligence

CVE-2026-56031: Uncanny Owl Uncanny Automator PHP object injection

CVE-2026-56031 · Severity: high · CVSS 8.1 · Published 2026-06-26

Technologies: Uncanny Owl Uncanny Automator. Vendors: Uncanny Owl.

Executive brief

Uncanny Automator, a popular WordPress plugin used to automate workflows between different apps and plugins, is vulnerable to a security flaw that allows unauthorized users to inject malicious data. If exploited, an attacker could potentially take control of the website, steal sensitive data, or disrupt services. This vulnerability is considered high priority because it does not require a login to exploit, though it may depend on specific site configurations.

Technical details

A PHP Object Injection vulnerability exists in the Uncanny Automator plugin for WordPress (versions <= 7.3.1.2) due to improper deserialization of user-supplied input. An unauthenticated remote attacker can exploit this by submitting specially crafted input to a vulnerable endpoint. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or arbitrary file deletion. The vulnerability is mitigated in version 7.3.1.3. While unauthenticated, the CVSS vector indicates high complexity (AC:H), suggesting specific preconditions or configurations may be required for successful exploitation.

Affected products

  • Uncanny Owl Uncanny Automator <= 7.3.1.2

Timeline

  • 2026-06-08: other: Reported by researcher VanTastic
  • 2026-06-23: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: CVE published to NVD
  • 2026-06-26: patched: Fixed in version 7.3.1.3

References

Related threats