Extension WordPress

Vulnérabilités AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

Cette page rassemble les failles publiées pour AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
1Critiques
12Avec correctif
9,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

12 fiches

CVE-2026-42775 Élevée · 7,2
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 – Unauthenticated Stored Cross-Site Scripting

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping.…

Versions affectées

*-5.7.2

Correctif

5.7.3

Publication

03/06/2026

CVE-2026-42650 Élevée · 7,2
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 – Unauthenticated Stored Cross-Site Scripting

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.7 due to insufficient input sanitization and output escaping.…

Versions affectées

*-5.6.7

Correctif

5.6.8

Publication

29/04/2026

CVE-2026-40785 Moyenne · 4,3
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 – Missing Authorization

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-5.6.7

Correctif

5.6.8

Publication

23/04/2026

CVE-2025-9539 Élevée · 8,0
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 – Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up…

Versions affectées

*-5.3.6

Correctif

5.3.7

Publication

08/09/2025

CVE-2025-9542 Moyenne · 5,4
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 5.3.7 – Authenticated (Subscriber+) Missing Authorization to Multiple Functions

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all…

Versions affectées

*-5.3.7

Correctif

5.3.8

Publication

08/09/2025

CVE-2025-68561 Moyenne · 4,9
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 5.2.4 – Authenticated (Administrator+) SQL Injection

The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-5.2.4

Correctif

5.2.5

Publication

19/06/2025

CVE-2025-5487 Élevée · 7,2
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 5.2.5 – Authenticated (Administrator+) SQL Injection via field_conditions

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient…

Versions affectées

*-5.2.5

Correctif

5.2.6

Publication

13/06/2025

CVE-2025-48280 Moyenne · 4,9
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 5.2.1.3 – Authenticated (Administrator+) SQL Injection

The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-5.2.1.3

Correctif

5.2.2

Publication

19/05/2025

CVE-2024-12626 Critique · 9,6
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 5.0.9 – Reflected Cross-Site Scripting via a-0-o-search_field_value

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient…

Versions affectées

*-5.0.9

Correctif

5.1.0

Publication

18/12/2024

Vulnérabilité Moyenne · 4,3
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 2.5.8 – Cross Site Request Forgery via bulk_delete

The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8. This is due to missing or incorrect nonce validation on the bulk_delete() function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.5.8

Correctif

2.5.9

Publication

14/02/2023

CVE-2023-23992 Moyenne · 4,3
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 2.5.0 – Cross Site Request Forgery

The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. This is due to missing nonce validation on the delete() function. This makes it possible for unauthenticated attackers to delete…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

20/01/2023

CVE-2021-24717 Élevée · 8,8
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

AutomatorWP <= 1.7.5 – Privilege Escalation

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

Versions affectées

[*, 1.7.6)

Correctif

1.7.6

Publication

28/09/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités