CVE-2026-12375: Unknown Uncanny-Automator-Pro

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.

Affected products

  • Unknown Uncanny-Automator-Pro: from 7.3.0.5, before 7.3.0.6 (fixed in 7.3.0.6)

Published 2026-07-07. Last modified 2026-07-07.