Vulnerabilities / AutomatorWP / WPSEC-2026-0506

AutomatorWP <= 6.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Pending Redirect URL Disclosure

Low 3.1 CWE-639Fixed in 6.0.4
ID
WPSEC-2026-0506
Plugin
AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI (automatorwp)
Affected
from 1.4.3 before 6.0.4
Remediation
Update to 6.0.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
AutomatorWP on WPSec AttackSurface
Fix released
Published

Description

The AutomatorWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 1.4.3 up to, and including, 6.0.3 due to the automatorwp_check_for_redirect AJAX action returning the pending redirect URL stored for a user ID taken from the request without checking that it belongs to the logged-in user. This makes it possible for authenticated attackers, with subscriber-level access and above, to read another user's pending 'Redirect user to URL' destination while one is waiting to be delivered, and to clear it so the other user is not redirected. The URL is the one configured by the site administrator and contains user-specific information only if the administrator included automation tags in it.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0