CyberRota Analysis
AI-GeneratedThe uncanny-automator-pro WordPress plugin versions prior to 7.3.0.6 contain a backdoor due to a compromise in the vendor's distribution infrastructure, allowing unauthenticated attackers to gain administrator access to affected sites. This vulnerability can lead to the exposure of sensitive site information, including secret keys and administrator credentials. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access and potential data breaches.
Original NVD Description
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.