
CVE-2026-12375 Uncanny Automator WordPress plugin update can grant unauthenticated admin access exposing secret keys, making plugin supply chains a serious website security risk Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-07/TIER_2_CVE-2026-12375.md #CyberSecurity #SupplyChainSecurity #VulnerabilityManagement
Post summary
CVE‑2026‑12375 affects the Uncanny Automator WordPress plugin by permitting unauthenticated administrators to access and expose secret keys; a detailed report is linked but no PoC, exploit code, patch, or active exploitation evidence is provided.
