{
 "id": "WPSEC-2026-0506",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0506/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0506/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0506/index.md",
 "title": "AutomatorWP <= 6.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Pending Redirect URL Disclosure",
 "description": "The AutomatorWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 1.4.3 up to, and including, 6.0.3 due to the automatorwp_check_for_redirect AJAX action returning the pending redirect URL stored for a user ID taken from the request without checking that it belongs to the logged-in user. This makes it possible for authenticated attackers, with subscriber-level access and above, to read another user's pending 'Redirect user to URL' destination while one is waiting to be delivered, and to clear it so the other user is not redirected. The URL is the one configured by the site administrator and contains user-specific information only if the administrator included automation tags in it.",
 "plugin": {
  "slug": "automatorwp",
  "name": "AutomatorWP",
  "full_name": "AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI",
  "wordpress_org": "https://wordpress.org/plugins/automatorwp/",
  "advisories_url": "https://wpsec.com/vuln/plugin/automatorwp/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/automatorwp"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.1,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.4.3",
    "from_inclusive": true,
    "to": "6.0.4",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.4.3 before 6.0.4"
  ]
 },
 "introduced_in": "1.4.3",
 "fixed_in": "6.0.4",
 "remediation": "Update to 6.0.4 or later.",
 "fix_released": "2026-10-04T21:05:55+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-07T10:53:25.385968+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0506/",
  "https://plugins.svn.wordpress.org/automatorwp/tags/6.0.4/",
  "https://wordpress.org/plugins/automatorwp/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/automatorwp",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}