Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 7, 2026
Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
CVE-2026-12375
Description
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
Affected products
2<7.3.0.6+ 1 more
- (no CPE)range: <7.3.0.6
- (no CPE)range: <7.3.0.6
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/ddc83705-3df6-427c-957b-935135330f73/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.