SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12375

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The uncanny-automator-pro WordPress plugin versions prior to 7.3.0.6 contain a backdoor due to a compromise in the vendor's distribution infrastructure, allowing unauthenticated attackers to gain administrator access to affected sites. This vulnerability can lead to the exposure of sensitive site information, including secret keys and administrator credentials. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access and potential data breaches.

CVE
CVE-2026-12375
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%
WordPress

Original NVD Description

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.