CVE-2026-12375: Unknown Uncanny-Automator-Pro
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
Affected products
- Unknown Uncanny-Automator-Pro: from 7.3.0.5, before 7.3.0.6 (fixed in 7.3.0.6)
Published 2026-07-07. Last modified 2026-07-07.