CVE-2025-68561: high-severity vulnerability in Ruben Garcia AutomatorWP
WordPress AutomatorWP plugin <= 5.2.4 - SQL Injection vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Affected products
Ruben Garcia · AutomatorWPRelated CVEs — Ruben Garcia AutomatorWP
In the same product, most dangerous first.
CVE-2026-40785HIGHWordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2025-48280HIGHWordPress AutomatorWP plugin <= 5.2.1.3 - SQL Injection VulnerabilityEPSS 0.3%CVE-2026-78266MEDIUMWordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-42650HIGHWordPress AutomatorWP plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-42775HIGHWordPress AutomatorWP plugin <= 5.7.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%