CVE-2026-15025

Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajax_fetch_labels, segments_fetch, tags_fetch, and render_contact_fields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.


We have discovered 401 live websites that are affected by CVE-2026-15025.

Run a Free Instant Scan




Affected Software

Product  Uncanny Automator
Category Wordpress Plugins
Vulnerable Domains401 live websites (100% of Uncanny Automator install base)
Vulnerable Versions
  • from 0 through 7.3.2
Vulnerable Versions Count39 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • thevietronin (finder)

Website Distribution by Country

Number of websites using CVE-2026-15025
United States162 websites



Japan21 websites
Germany19 websites
GB19 websites
France15 websites
Italy12 websites
Spain12 websites
Canada11 websites
Brazil10 websites
Australia10 websites

Website Distribution by TLD

Number of websites using CVE-2026-15025
.com206 websites
.org21 websites
.net16 websites
.co.uk10 websites
.com.br10 websites
.com.au8 websites
.fr7 websites
.ca7 websites
.it7 websites
.es6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15025

Top websites that are affected by CVE-2026-15025. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States**,***
**********.com Cyprus***,***
**********.***.au United States***,***
**********.com Canada***,***
************.com Germany***,***
*****.org Germany***,***
*******.**.jp Japan***,***
**************.com United States*,***,***
*******.org Canada*,***,***
****************.com United States*,***,***
See full domain list

FAQ

CVE-2026-15025 is Missing Authorization in Uncanny Automator
A total of 401 websites have been identified as vulnerable to CVE-2026-15025, based on global website indexing conducted by WebTechSurvey.
The Uncanny Automator is affected by the CVE-2026-15025 vulnerability.
Uncanny Automator versions up to and including 7.3.2 are vulnerable to CVE-2026-15025.

References