rubengc Vulnerabilities and Affected Products
Vulnerabilities associated with AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress.
Products
Clear product- GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress11 vulnerabilities
- AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress4 vulnerabilities
- GamiPress – Button1 vulnerability
- GamiPress – Link1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-9539HIGH | AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation CreationThe AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up to, and including, 5.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary automations, which can lead to Remote Code Execution or Privilege escalat… CWE-94Sep 9, 2025 | CVSS8.0v3.1 | EPSS0.446% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9542MEDIUM | AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple FunctionsThe AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify integration settings or view existing automations. CWE-862Sep 9, 2025 | CVSS5.4v3.1 | EPSS0.192% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5487HIGH | AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditionsThe AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries int… CWE-89Jun 14, 2025 | CVSS7.2v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12626CRITICAL | AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_valueThe AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as… CWE-79Dec 19, 2024 | CVSS9.6v3.1 | EPSS0.747% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |