CVE-2026-15025
Description
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajax_fetch_labels, segments_fetch, tags_fetch, and render_contact_fields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=7.3.2+ 1 more
- (no CPE)range: <=7.3.2
- (no CPE)range: <=7.3.2
Patches
Vulnerability mechanics
References
14- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/google-contacts/google-contacts-integration.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/google-contacts/helpers/google-contacts-helper.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/mautic-integration.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/google-contacts/google-contacts-integration.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/google-contacts/helpers/google-contacts-helper.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.phpnvd
- plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/mautic-integration.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/1bfa1538-7722-458d-a6a5-adde03e21e1anvd
News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)Wordfence Blog · Aug 8, 2026