Vulnerability  ·  2026-10-09

Uncanny Automator (AI + Automation for WordPress) PHP object injection via deserialization of untrusted input

VulnerabilityMedium impactGlobalCVE-2026-82627
NVD published CVE-2026-82627 on 2026-10-08 for a PHP Object Injection (CWE-502) in Uncanny Automator's AI + Automation WordPress plugin up to 7.6.1.1, via deserialization of untrusted input, exploitable by an authenticated attacker (requires a non-admin role).
WordPress AI-automation plugins sit inside sites that increasingly orchestrate AI content/agent actions; object injection here is a classic PHP pop-chain surface that, given a gadget, escalates from a low-privilege user to arbitrary code on the site — and the SEO/content AI plugin class is a common target in the AI-plugin supply chain.
Authenticated (contributor+) attacker triggers deserialization of untrusted input, a PHP object injection that can lead to arbitrary file deletion/read, SSRF, or in chained gadget scenarios code execution, inside the AI automation plugin's request handling.
Uncanny Automator – AI + Automation for WordPress ≤ 7.6.1.1 (fixed in subsequent release; changeset 3721435)
Update Uncanny Automator to the patched version (plugin Trac changeset 3721435); restrict which roles can access plugin endpoints in the interim.
WordPress plugin Trac changesetNVD entry
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →