AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Unauthenticated Stored Cross-Site Scripting
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
Minimum safe version
5.6.8
Update to 5.6.8 or later to address 12 fixable vulnerabilities
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization
AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation
CVE-2025-68561
AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions
CVE-2025-48280
CVE-2024-12626
WordPress AutomatorWP Plugin <= 2.5.8 is vulnerable to Cross Site Request Forgery (CSRF)
AutomatorWP <= 2.5.8 - Cross Site Request Forgery via bulk_delete
CVE-2023-23992
CVE-2021-24717