CVE-2026-2269Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Additionally, the plugin stores the contents of the remote files on the server, which can be leveraged to upload arbitrary files on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-03); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 103-0303-04
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-032
Disclosure2
2026-03-041
Patch1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2269 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… https://www.cve.org/CVERecord?id=CVE-2026-2269 ----- Traducción: CVE-2026-2269 The… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑2269, a Server‑Side Request Forgery vulnerability in the Uncanny Automator WordPress plugin, without mentioning PoC, exploit, or patch details.

    1000035
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2269 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… https://www.cve.org/CVERecord?id=CVE-2026-2269

    Post summary

    CVE-2026-2269 is a server‑side request forgery affecting all versions of the Uncanny Automator WordPress plugin, with no PoC, exploit, or patch details provided.

    10000225
    56.6K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 WordPress Admins! Beware of CVE-2026-2269: Uncanny Automator (≤ 7.0.0.3) is vulnerable to SSRF, allowing unauthorized file uploads and remote code execution. Update your plugins ASAP or disable them! Stay secure! 🔒 #Cybersecurity #WordPress #SSRF https://www.tenable.com/cve/CVE-2026-2269

    Post summary

    The post alerts WordPress admins to a CVE‑2026‑2269 SSRF flaw in Uncanny Automator, urging them to update or disable the plugin to prevent remote code execution.

    0000078
    255 followersView on X

Explore more