PT-2025-36578 · WordPress · Automatorwp

Matthew Rollings

·

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-9539

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: AutomatorWP – Automator plugin for WordPress versions prior to 5.3.7
Description: The AutomatorWP – Automator plugin for WordPress is susceptible to unauthorized data modification due to a missing capability check on the automatorwp ajax import automation from url function. This allows authenticated attackers with Subscriber-level access or higher to create arbitrary automations, potentially leading to Remote Code Execution or Privilege escalation when activated by an administrator.
Recommendations: Update AutomatorWP – Automator plugin for WordPress to version 5.3.7 or later.

Fix

LPE

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9539

Affected Products

Automatorwp