top of page
perceptive_background_267k.jpg

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7…

Published:

6 juli 2026 om 22:00:00

Alert date:

7 juli 2026 om 15:02:11

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies, Identity & Access, Data Breach & Exfiltration

The uncanny-automator-pro WordPress plugin versions before 7.3.0.6 were distributed with malicious code following a supply chain compromise of the vendor's update and distribution infrastructure. The injected backdoor allows unauthenticated attackers to obtain administrator-level sessions on affected WordPress sites. Additionally, the malicious code beacons sensitive data including the site's secret keys and administrator credentials to attacker-controlled servers. This represents a critical supply chain attack targeting WordPress site owners who installed or updated the plugin before the patched version 7.3.0.6 was released. Site owners running affected versions should immediately update the plugin, rotate secret keys, and audit administrator accounts for unauthorized access. The vulnerability is tracked as CVE-2026-12375 and has been documented by both NVD and WPScan.

Technical details

Mitigation steps:

Affected products:

uncanny-automator-pro WordPress plugin before 7.3.0.6

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page