PT-2026-65446 · Uncanny Owl · The Uncanny Automator – Easy Automation

·

CVE-2026-15025

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator google contacts fetch labels, automator mautic segment fetch, automator mautic tags fetch, and automator mautic render contact fields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajax fetch labels, segments fetch, tags fetch, and render contact fields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15025

Affected Products

The Uncanny Automator – Easy Automation