VYPR
Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 7, 2026

Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server

CVE-2026-12375

Description

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.