Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

WordPress Automatic Plugin Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 10 vulnerability records associated with WordPress Automatic Plugin, published between 2014 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

10Total records
4Critical
3High
3Medium
0Low
0Informational
10Patched records
0Currently marked unpatched
2014-08-01First disclosure
2026-06-25Latest disclosure
9 of 10CVE coverage

Use this history

Check and watch WordPress Automatic Plugin.

A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.

Year-by-Year Timeline

YearRecordsRelative volume
201411 records
202111 records
202455 records
202522 records
202611 records

Severity Breakdown

SeverityRecordsShare
Critical440%
High330%
Medium330%

Vulnerability-Type Breakdown

Cross-Site Scripting

3 records30%

First: 2024. Latest: 2026.

SQL Injection

2 records20%

First: 2014. Latest: 2024.

CSRF

2 records20%

First: 2024. Latest: 2024.

Missing Authorization

1 record10%

First: 2021. Latest: 2021.

Other

1 record10%

First: 2024. Latest: 2024.

Arbitrary File Upload

1 record10%

First: 2025. Latest: 2025.

Patch Status

Patched
10
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.135.1
  • 3.119.0
  • 3.116.0
  • 3.95.0
  • 3.93.0
  • 3.92.1
  • 3.53.3
  • 2.0.4

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
[*, 3.135.1)WordPress Automatic Plugin < 3.135.1 - Unauthenticated Stored Cross-Site ScriptingJune 25, 20263.135.1High
*-3.118.0WordPress Automatic Plugin - AI content generator and auto poster plugin <= 3.118.0 - Cross-Site Request Forgery to Stored Cross-Site ScriptingAugust 25, 20253.119.0Medium
*-3.115.0WordPress Automatic Plugin - AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File UploadJune 10, 20253.116.0High
*-3.94.0WordPress Automatic <= 3.94.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay ParameterMay 17, 20243.95.0Medium
*-3.92.1WordPress Automatic Plugin <= 3.92.1 Cross-Site Request ForgeryApril 19, 20243.93.0Medium
*-3.92.0Automatic <= 3.92.0 - Unauthenticated SQL InjectionMarch 13, 20243.92.1Critical
*-3.92.0Automatic <= 3.92.0 - Unauthenticated Arbitrary File Download and Server-Side Request ForgeryMarch 13, 20243.92.1Critical
*-3.92.0Automatic <= 3.92.0 - Cross-Site Request Forgery to Privilege EscalationMarch 13, 20243.92.1High
[*, 3.53.3)WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options UpdateSeptember 6, 20213.53.3Critical
*-2.0.3WordPress Automatic Plugin <= 2.0.3 - Cross-Site Request Forgery to SQL InjectionAugust 1, 20142.0.4Critical

Selected source records

Latest Records

HighCVE-2026-56045

WordPress Automatic Plugin < 3.135.1 - Unauthenticated Stored Cross-Site Scripting

Published: June 25, 2026

Affected versions
[*, 3.135.1)
Patched versions
3.135.1
Original Wordfence record
MediumCVE-2025-6247

WordPress Automatic Plugin - AI content generator and auto poster plugin <= 3.118.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Published: August 25, 2025

Affected versions
*-3.118.0
Patched versions
3.119.0
Original Wordfence record
HighCVE-2025-5395

WordPress Automatic Plugin - AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File Upload

Published: June 10, 2025

Affected versions
*-3.115.0
Patched versions
3.116.0
Original Wordfence record
MediumCVE-2024-4849

WordPress Automatic <= 3.94.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay Parameter

Published: May 17, 2024

Affected versions
*-3.94.0
Patched versions
3.95.0
Original Wordfence record
MediumCVE-2024-32693

WordPress Automatic Plugin <= 3.92.1 Cross-Site Request Forgery

Published: April 19, 2024

Affected versions
*-3.92.1
Patched versions
3.93.0
Original Wordfence record
HighCVE-2024-27955

Automatic <= 3.92.0 - Cross-Site Request Forgery to Privilege Escalation

Published: March 13, 2024

Affected versions
*-3.92.0
Patched versions
3.92.1
Original Wordfence record
CriticalCVE-2024-27954

Automatic <= 3.92.0 - Unauthenticated Arbitrary File Download and Server-Side Request Forgery

Published: March 13, 2024

Affected versions
*-3.92.0
Patched versions
3.92.1
Original Wordfence record
CriticalCVE-2024-27956

Automatic <= 3.92.0 - Unauthenticated SQL Injection

Published: March 13, 2024

Affected versions
*-3.92.0
Patched versions
3.92.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-27954

Automatic <= 3.92.0 - Unauthenticated Arbitrary File Download and Server-Side Request Forgery

Published: March 13, 2024

Affected versions
*-3.92.0
Patched versions
3.92.1
Original Wordfence record
CriticalCVE-2024-27956

Automatic <= 3.92.0 - Unauthenticated SQL Injection

Published: March 13, 2024

Affected versions
*-3.92.0
Patched versions
3.92.1
Original Wordfence record
Critical

WordPress Automatic Plugin <= 2.0.3 - Cross-Site Request Forgery to SQL Injection

Published: August 1, 2014

Affected versions
*-2.0.3
Patched versions
2.0.4
Original Wordfence record
CriticalCVE-2021-4374

WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update

Published: September 6, 2021

Affected versions
[*, 3.53.3)
Patched versions
3.53.3
Original Wordfence record
HighCVE-2024-27955

Automatic <= 3.92.0 - Cross-Site Request Forgery to Privilege Escalation

Published: March 13, 2024

Affected versions
*-3.92.0
Patched versions
3.92.1
Original Wordfence record
HighCVE-2025-5395

WordPress Automatic Plugin - AI content generator and auto poster plugin <= 3.115.0 - Authenticated (Author+) Arbitrary File Upload

Published: June 10, 2025

Affected versions
*-3.115.0
Patched versions
3.116.0
Original Wordfence record
HighCVE-2026-56045

WordPress Automatic Plugin < 3.135.1 - Unauthenticated Stored Cross-Site Scripting

Published: June 25, 2026

Affected versions
[*, 3.135.1)
Patched versions
3.135.1
Original Wordfence record
MediumCVE-2024-4849

WordPress Automatic <= 3.94.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay Parameter

Published: May 17, 2024

Affected versions
*-3.94.0
Patched versions
3.95.0
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory