Executive brief
Uncanny Automator Pro is a WordPress plugin used to create automated workflows between different apps and plugins. A critical security flaw allows remote attackers to inject malicious code into the website. If exploited, this could lead to full site takeover, data theft, or the complete deletion of website content.
Technical details
A PHP Object Injection vulnerability exists in Uncanny Automator Pro versions up to and including 7.3.0.6. The flaw stems from the deserialization of untrusted data (CWE-502), which can be triggered by an unauthenticated user. If a suitable Property-Oriented Programming (POP) chain is present on the server, an attacker can leverage this to execute arbitrary code, perform SQL injection, or achieve path traversal. The vulnerability is resolved in version 7.3.0.7.
Affected products
- Uncanny Owl Uncanny Automator Pro <= 7.3.0.6
Timeline
- 2026-06-18: other: Reported by VanTastic
- 2026-06-25: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date
- 7.3.0.7: patched