Junglewise Threat Intelligence

CVE-2026-78266: AutomatorWP broken access control in subscriber functions

CVE-2026-78266 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Technologies: AutomatorWP. Vendors: AutomatorWP.

Executive brief

AutomatorWP is a popular WordPress plugin that automates tasks and workflows on WordPress sites. This vulnerability allows subscriber-level users to access pages and perform actions they should not have permission to do, such as viewing other users' data or executing restricted operations. An attacker with a subscriber account could escalate their privileges beyond what should be allowed.

Technical details

This is a broken access control vulnerability (CWE-639) in AutomatorWP versions up to and including 5.8.3. The vulnerability allows users with the subscriber role to bypass authorization checks and access functionality or data restricted to higher-privilege roles. The attack vector is network-based and requires the attacker to possess a valid subscriber account on the affected WordPress installation. An authenticated attacker can exploit this to view sensitive information or perform unauthorized administrative actions. The vulnerability is patched in version 5.8.4 and later.

Affected products

  • AutomatorWP AutomatorWP <= 5.8.3

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Version 5.8.4 or later
  • 2026-08-24: advisory: Patchstack advisory published

References

Related threats