What happened
NVD published CVE-2026-82627 on 2026-10-08 for a PHP Object Injection (CWE-502) in Uncanny Automator's AI + Automation WordPress plugin up to 7.6.1.1, via deserialization of untrusted input, exploitable by an authenticated attacker (requires a non-admin role).
Why it matters
WordPress AI-automation plugins sit inside sites that increasingly orchestrate AI content/agent actions; object injection here is a classic PHP pop-chain surface that, given a gadget, escalates from a low-privilege user to arbitrary code on the site — and the SEO/content AI plugin class is a common target in the AI-plugin supply chain.
Attack vector
Authenticated (contributor+) attacker triggers deserialization of untrusted input, a PHP object injection that can lead to arbitrary file deletion/read, SSRF, or in chained gadget scenarios code execution, inside the AI automation plugin's request handling.
Affected systems
Uncanny Automator – AI + Automation for WordPress ≤ 7.6.1.1 (fixed in subsequent release; changeset 3721435)
Mitigation
Update Uncanny Automator to the patched version (plugin Trac changeset 3721435); restrict which roles can access plugin endpoints in the interim.