Extension WordPress
Vulnérabilités AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
Cette page rassemble les failles publiées pour AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
12 fiches
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 – Unauthenticated Stored Cross-Site Scripting
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping.…
*-5.7.2
5.7.3
03/06/2026
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 – Unauthenticated Stored Cross-Site Scripting
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.7 due to insufficient input sanitization and output escaping.…
*-5.6.7
5.6.8
29/04/2026
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 – Missing Authorization
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-5.6.7
5.6.8
23/04/2026
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 – Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up…
*-5.3.6
5.3.7
08/09/2025
AutomatorWP <= 5.3.7 – Authenticated (Subscriber+) Missing Authorization to Multiple Functions
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all…
*-5.3.7
5.3.8
08/09/2025
AutomatorWP <= 5.2.4 – Authenticated (Administrator+) SQL Injection
The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.2.4
5.2.5
19/06/2025
AutomatorWP <= 5.2.5 – Authenticated (Administrator+) SQL Injection via field_conditions
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient…
*-5.2.5
5.2.6
13/06/2025
AutomatorWP <= 5.2.1.3 – Authenticated (Administrator+) SQL Injection
The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.2.1.3
5.2.2
19/05/2025
AutomatorWP <= 5.0.9 – Reflected Cross-Site Scripting via a-0-o-search_field_value
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient…
*-5.0.9
5.1.0
18/12/2024
AutomatorWP <= 2.5.8 – Cross Site Request Forgery via bulk_delete
The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8. This is due to missing or incorrect nonce validation on the bulk_delete() function. This makes it possible for unauthenticated attackers…
*-2.5.8
2.5.9
14/02/2023
AutomatorWP <= 2.5.0 – Cross Site Request Forgery
The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. This is due to missing nonce validation on the delete() function. This makes it possible for unauthenticated attackers to delete…
*-2.5.0
2.5.1
20/01/2023
AutomatorWP <= 1.7.5 – Privilege Escalation
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
[*, 1.7.6)
1.7.6
28/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.