# AutomatorWP <= 6.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Pending Redirect URL Disclosure

- **ID:** WPSEC-2026-0506
- **Plugin:** AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI (`automatorwp`), https://wordpress.org/plugins/automatorwp/
- **Affected versions:** from 1.4.3 before 6.0.4
- **Fixed in:** 6.0.4 (Update to 6.0.4 or later.)
- **Severity:** Low 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/automatorwp
- **Fix released:** 2026-10-04
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0506/

## Description

The AutomatorWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 1.4.3 up to, and including, 6.0.3 due to the automatorwp_check_for_redirect AJAX action returning the pending redirect URL stored for a user ID taken from the request without checking that it belongs to the logged-in user. This makes it possible for authenticated attackers, with subscriber-level access and above, to read another user's pending 'Redirect user to URL' destination while one is waiting to be delivered, and to clear it so the other user is not redirected. The URL is the one configured by the site administrator and contains user-specific information only if the administrator included automation tags in it.

## References

- https://wpsec.com/vuln/WPSEC-2026-0506/
- https://plugins.svn.wordpress.org/automatorwp/tags/6.0.4/
- https://wordpress.org/plugins/automatorwp/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0506/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
