CVE-2026-76057Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all ConvertKit form data configured by the site's manager account, exposing integration details intended to be restricted to plugin managers. The required nonce is localized on every admin page load, making it accessible to any authenticated user who can reach /wp-admin.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-22: 3Technical Details · 2026-08-22: 308-22
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-76057 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in … https://www.cve.org/CVERecord?id=CVE-2026-76057

    Post summary

    CVE-2026-76057 indicates an authorization bypass vulnerability in the AutomatorWP plugin for WordPress, notifying users of a potential security flaw.

    000201.4K
    58.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-76057 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in … https://www.cve.org/CVERecord?id=CVE-2026-76057 ----- Traducción: CVE-2026-76057 El … http://infoflow.cloud`

    Post summary

    The post references CVE-2026-76057 and notes an authorization bypass in the AutomatorWP WordPress plugin, but does not provide any PoC, exploit code, active exploitation evidence, or mitigation steps.

    0000030
    102 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-76057 Authorization Bypass in AutomatorWP Plugin Exposes ConvertKit Form Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-76057

    Post summary

    A new authorization bypass vulnerability (CVE-2026-76057) in AutomatorWP plugin exposes ConvertKit form data, with no evidence of exploitation or mitigation referenced.

    00000125
    4.1K followersView on X

Explore more