Description
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version
Timeline
| 2025-05-13: | Disclosed |
Credits
Michael Mazzolini
Gai Tanaka
References
www.wordfence.com/...-9785-449a-a0ea-16e2583d684a?source=cve
wordpress.org/plugins/uncanny-automator/
plugins.trac.wordpress.org/...s-automator-recipe-helpers.php
plugins.trac.wordpress.org/...s-automator-recipe-helpers.php
automatorplugin.com/...dge-base/uncanny-automator-changelog/