Vulnerabilities / AutomatorWP
AutomatorWP vulnerabilities
Advisories WPSec published for AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI. Other sources may list more. Its attack surface: AutomatorWP on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-07 | WPSEC-2026-0506 | AutomatorWP <= 6.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Pending Redirect URL Disclosure | Low 3.1 | 6.0.4 |
License: CC BY 4.0