Sceawere

Vulnerability Detail

CVE-2026-104728UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AutomatorWP Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
rubengc
Product
AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate all Fluent Forms records, including form IDs and titles, from the fluentform_forms database table.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-10T08:17:03.933Z",
  "pubdate": "2026-10-10T08:17:03.933Z",
  "executiveSummary": "The AutomatorWP plugin for WordPress, specifically versions 5.8.4 and earlier, contains an authorization bypass vulnerability.\nThis security flaw stems from inadequate access control validation within the plugin's action handling mechanisms.\nThe vulnerability allows authenticated users with minimal privileges, such as subscribers, to perform unauthorized actions.\nSpecifically, an attacker can enumerate sensitive information from the underlying database, including the IDs and titles of all Fluent Forms integrated with the plugin.\nThis represents an unauthorized information disclosure risk, as it permits low-privileged users to map backend form structures and metadata.\nNo complex exploitation vectors are required beyond standard authenticated access to the WordPress environment.\nThe impact is categorized as an improper access control vulnerability, which could potentially serve as a precursor to further reconnaissance or targeted attacks against form-based data.",
  "technicalDetails": "The vulnerability resides in the plugin's failure to perform sufficient capability checks when processing requests intended for integration retrieval. In the AutomatorWP plugin versions up to 5.8.4, the endpoint responsible for fetching Fluent Forms metadata lacks a robust authorization layer.\nUnder normal operations, administrative or authorized workflows expect to query the fluentform_forms database table to populate automation triggers. However, the plugin fails to verify the current user's role or capabilities before executing these database queries.\nExploitation is trivial for any authenticated user. Because the application logic does not validate the security context of the incoming request, the underlying API or AJAX handler executes the function responsible for querying Fluent Forms regardless of the caller's privilege level.\nAn attacker can craft a request that triggers the specific plugin function designed to list Fluent Forms. By sending this request to the WordPress REST API or the relevant admin-ajax endpoint utilized by AutomatorWP, the server processes the database query against the fluentform_forms table.\nThe server subsequently returns a serialized list of form IDs and titles, which are then exposed to the subscriber-level user in the response body.\nThis information disclosure is categorized as an authorization bypass because the plugin relies on client-side interface restrictions or incorrect assumptions about request origin rather than server-side enforcement of WordPress user capabilities (e.g., current_user_can('manage_options')).\nThe attack flow follows these steps: 1. The attacker authenticates as a standard subscriber. 2. The attacker identifies the vulnerable API endpoint or AJAX action utilized by AutomatorWP for Fluent Forms integration. 3. The attacker submits an authorized request to this endpoint. 4. The backend, lacking authorization checks, executes the database query. 5. The backend returns the list of form identifiers and titles to the attacker.\nPost-exploitation, the attacker gains architectural awareness of the WordPress installation's form infrastructure. While this vulnerability does not immediately result in remote code execution, it facilitates reconnaissance that can be used to identify high-value forms for subsequent attacks or social engineering, effectively bypassing the security boundaries intended by the plugin's configuration."
}
CVE-2026-104728: AutomatorWP Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere