Executive brief
AutomatorWP is a popular WordPress plugin that automates tasks and workflows on WordPress sites. This vulnerability allows subscriber-level users to access pages and perform actions they should not have permission to do, such as viewing other users' data or executing restricted operations. An attacker with a subscriber account could escalate their privileges beyond what should be allowed.
Technical details
This is a broken access control vulnerability (CWE-639) in AutomatorWP versions up to and including 5.8.3. The vulnerability allows users with the subscriber role to bypass authorization checks and access functionality or data restricted to higher-privilege roles. The attack vector is network-based and requires the attacker to possess a valid subscriber account on the affected WordPress installation. An authenticated attacker can exploit this to view sensitive information or perform unauthorized administrative actions. The vulnerability is patched in version 5.8.4 and later.
Affected products
- AutomatorWP AutomatorWP <= 5.8.3
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Version 5.8.4 or later
- 2026-08-24: advisory: Patchstack advisory published