Uncanny Automator WordPress Plugin Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the Uncanny Automator WordPress plugin, specifically in versions through 7.3.1.4. This issue arises from inadequate file path validation in the 'fr_token' function, enabling unauthenticated attackers to delete arbitrary files on the server. Exploitation of this vulnerability could lead to remote code execution, particularly if sensitive files like 'wp-config.php' are targeted. The vulnerability can be exploited by submitting a malicious serialized payload through an unauthenticated Forminator form connected to an Uncanny Automator recipe set for 'Everyone'.

Impact

Successful exploitation allows for arbitrary file deletion on the server, which can lead to remote code execution if a critical file is deleted.

Reproduction

To reproduce this vulnerability, an unauthenticated user must submit a Forminator form that is linked to an Uncanny Automator recipe allowing submissions from everyone. The submission must include a malicious serialized payload designed to exploit the file deletion vulnerability. This can be achieved by targeting the 'fr_token' function, which lacks proper validation of file paths.

Remediation

Users are advised to update the Uncanny Automator WordPress plugin to version 7.4.0 or later.

Added: Jul 16, 2026, 9:46 AM
Updated: Jul 16, 2026, 9:46 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
8.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.