Skip to content
CVE / MITRECVE Recent··1 min read

CVE-2026-15008 - Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token

CVE ID :CVE-2026-15008 Published : July 16, 2026, 7:51 a. m. | 1 hour, 7 minutes ago Description :The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.

3. 1. 4.

Originally reported by CVE Recent
0 comments

0 comments

Posting as BoldOtter423
0/1000

No comments yet. Be the first to start the discussion.