


Perceptive Security
SOC/SIEM Consultancy

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7…
Published:
6 juli 2026 om 22:00:00
Alert date:
7 juli 2026 om 15:02:11
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Identity & Access, Data Breach & Exfiltration
The uncanny-automator-pro WordPress plugin versions before 7.3.0.6 were distributed with malicious code following a supply chain compromise of the vendor's update and distribution infrastructure. The injected backdoor allows unauthenticated attackers to obtain administrator-level sessions on affected WordPress sites. Additionally, the malicious code beacons sensitive data including the site's secret keys and administrator credentials to attacker-controlled servers. This represents a critical supply chain attack targeting WordPress site owners who installed or updated the plugin before the patched version 7.3.0.6 was released. Site owners running affected versions should immediately update the plugin, rotate secret keys, and audit administrator accounts for unauthorized access. The vulnerability is tracked as CVE-2026-12375 and has been documented by both NVD and WPScan.
Technical details
Mitigation steps:
Affected products:
uncanny-automator-pro WordPress plugin before 7.3.0.6
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-12375
https://wpscan.com/vulnerability/ddc83705-3df6-427c-957b-935135330f73/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
