WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WPBot Automator – Automation for WordPress, Visual No-Code WorkFlow Builder

Automation plugin for WordPress with a visual no-code builder. Create automated workflows to connect WordPress, WooCommerce, WPForms, & more

13Reported vulnerabilities
9.8Highest CVSS score
1.3.1Latest version
30+Active installs

What to do now

Update WPBot Automator – Automation for WordPress, Visual No-Code WorkFlow Builder to 4.9.7 or later. 13 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 1, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-1650 Critical 9.8 34.4% Before 4.4.7 4.4.7 May 8, 2023
CVE-2023-1660 Medium 6.1 0.3% Before 4.4.9 4.4.9 May 8, 2023
CVE-2023-1011 Medium 6.1 0.2% Before 4.4.5 4.4.5 May 8, 2023
CVE-2023-5533 Critical 9.8 0.5% 4.8.9 and earlier
4.9.2 to 4.9.2 (inclusive)
4.9.1 October 20, 2023
CVE-2023-1651 Medium 5.4 0.2% Before 4.4.9 4.4.9 May 8, 2023
CVE-2023-4254 Medium 4.8 0.5% Before 4.7.8 4.7.8 September 4, 2023
CVE-2023-4253 Medium 4.8 0.5% Before 4.7.8 4.7.8 September 4, 2023
CVE-2023-3175 Medium 4.8 0.6% Before 4.6.1 4.6.1 July 10, 2023
CVE-2023-2811 Medium 4.8 0.4% Before 4.5.6 4.5.6 June 19, 2023
CVE-2023-2742 Medium 4.8 0.5% Before 4.5.5 4.5.5 June 19, 2023
CVE-2023-1649 Medium 4.8 0.4% Before 4.5.1 4.5.1 May 8, 2023
CVE-2023-5534 Medium 5.4 0.2% 4.8.9 and earlier
4.9.2 to 4.9.2 (inclusive)
4.9.1 October 20, 2023
CVE-2023-5606 Medium 4.8 0.3% 4.8.6 up to (but not including) 4.9.7 4.9.7 November 2, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.