CVE detail
CVE-2026-15025
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajax_fetch_labels, segments_fetch, tags_fetch, and render_contact_fields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 14
- within the 30d window
- Peak daily
- 14
- highest bucket
Evidence
Source links by recency
14 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfa1538-7722-458d-a6a5-adde03e21e1a?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3607785%40uncanny-automator&new=3607785%40uncanny-automatorplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/mautic-integration.php#L60plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.php#L302plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.php#L250plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.php#L199plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/google-contacts/helpers/google-contacts-helper.php#L113plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/google-contacts/google-contacts-integration.php#L70plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/mautic-integration.php#L60plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.php#L302plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.php#L250plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.php#L199plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/google-contacts/helpers/google-contacts-helper.php#L113plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM - https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/google-contacts/google-contacts-integration.php#L70plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 28, 2026, 12:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66751CVSS 5.3 · Medium
Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to…
- CVE-2026-66750CVSS 5.3 · Medium
Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected…
- CVE-2026-16774CVSS 5.3 · Medium
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_sen…
- CVE-2026-15411CVSS 5.3 · Medium
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all vers…
- CVE-2026-13110CVSS 5.3 · Medium
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the b…
- CVE-2026-14168CVSS 8.8 · High
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system acce…