PatchSiren cyber security CVE debrief
CVE-2026-82627 uncannyowl CVE debrief
The Uncanny Automator – AI + Automation for WordPress plugin, version 7.6.1.1 and below, is vulnerable to PHP Object Injection. This vulnerability allows authenticated attackers with Subscriber-level access to inject a PHP Object when a third-party integration plugin is installed and a recipe is configured to store attacker-controlled data as trigger meta. The presence of a POP chain within Uncanny Automator enables attackers to delete arbitrary files on the server, potentially leading to significant system compromise and data loss. WordPress administrators and security teams should assess exposure and prioritize remediation.
- Vendor
- uncannyowl
- Product
- Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
WordPress administrators, security teams, and IT professionals responsible for managing WordPress installations and ensuring the security of related systems should assess exposure and prioritize remediation. This includes teams responsible for vulnerability management, incident response, and system hardening.
Why it matters
CVE-2026-82627 is a high-severity vulnerability in the Uncanny Automator plugin for WordPress, allowing authenticated attackers to delete arbitrary files. WordPress administrators and security teams should assess exposure and prioritize remediation.
- Verification of Uncanny Automator version and configuration is necessary to determine exposure.
- Authenticated attackers with Subscriber-level access can exploit this vulnerability.
- Arbitrary file deletion can lead to significant system compromise and data loss.
- Remediation priority is high due to the potential for system compromise.
Technical summary
The Uncanny Automator – AI + Automation for WordPress plugin is vulnerable to PHP Object Injection due to deserialization of untrusted input. Authenticated attackers with Subscriber-level access can inject a PHP Object when a third-party integration plugin is installed and a recipe is configured to store attacker-controlled data as trigger meta. The presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.
Defensive priority
High
Recommended defensive actions
- Review and update Uncanny Automator – AI + Automation for WordPress to a version greater than 7.6.1.1
- Restrict access to sensitive areas of the WordPress site
- Monitor for suspicious activity related to file deletions
- Verify Uncanny Automator configuration and third-party integration plugins for potential exposure
- Conduct a thorough review of system logs for signs of exploitation
- Implement additional monitoring and detection controls for high-severity vulnerabilities
- Consider restricting Subscriber-level access to sensitive areas of the site
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation and impact is limited. There is no evidence of public exploitation, but defenders should verify Uncanny Automator version and configuration to determine exposure. The CVE Program and NVD entries offer source-provided metadata and vulnerability assessments, but further details on potential impact and mitigation strategies are needed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82627 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82627
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82627 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82627
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Inc
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/82xxx/CVE-2026-82627.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3721435/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.