Company Details
automatorwp
1
249
5112
automatorwp.com
0
AUT_3191303
In-progress

AutomatorWP Company CyberSecurity Posture
automatorwp.comAutomatorWP is a flexible and open-source automator plugin that let's you connect your WordPress plugins together and create automated workflows. You can create "automations" linked to your WordPress activities and when any of them happen, you can make other things happen accordingly. You can use these automations for automating sales, marketing, administrative tasks, learning and any other kind of processes you want letting you save time and get focused on your most important work.
Company Details
automatorwp
1
249
5112
automatorwp.com
0
AUT_3191303
In-progress
Between 700 and 749

AutomatorWP Global Score (TPRM)XXXX

Description: A critical vulnerability, CVE-2024-13496, was discovered in the GamiPress WordPress plugin, potentially impacting numerous WordPress websites using the plugin for gamification and rewards systems. An unauthenticated SQL injection flaw enabled attackers to manipulate SQL queries, posing a high risk of sensitive data extraction and website compromise. Although there was no immediate evidence of exploitation, the vulnerability, with a CVSS score of 7.5, required urgent attention and patching. The potential losses could have included customer trust erosion, unauthorized access to personal data, and a consequential threat to the websites' integrity and reputation.


No incidents recorded for AutomatorWP in 2025.
No incidents recorded for AutomatorWP in 2025.
No incidents recorded for AutomatorWP in 2025.
AutomatorWP cyber incidents detection timeline including parent company and subsidiaries

AutomatorWP is a flexible and open-source automator plugin that let's you connect your WordPress plugins together and create automated workflows. You can create "automations" linked to your WordPress activities and when any of them happen, you can make other things happen accordingly. You can use these automations for automating sales, marketing, administrative tasks, learning and any other kind of processes you want letting you save time and get focused on your most important work.


Cadence is a market leader in AI and digital twins, pioneering the application of computational software to accelerate innovation in the engineering design of silicon to systems. Our design solutions, based on Cadence’s Intelligent System Design™ strategy, are essential for the world’s leading semic
The Bosch Group is a leading global supplier of technology and services. It employs roughly 417,900 associates worldwide (as of December 31, 2024). According to preliminary figures, the company generated sales of 90.5 billion euros in 2024. Its operations are divided into four business sectors: Mobi
Databricks is the Data and AI company. More than 10,000 organizations worldwide — including Block, Comcast, Condé Nast, Rivian, Shell and over 60% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to take control of their data and put it to work with AI. Databricks is headquarte
SAP is the leading enterprise application and business AI company. We stand at the intersection of business and technology, where our innovations are designed to directly address real business challenges and produce real-world impacts. Our solutions are the backbone for the world’s most complex and

[24]7.ai™ customer engagement solutions use conversational artificial intelligence to understand customer intent, enabling companies to create personalized, predictive, and effortless customer experiences across all channels; attract and retain customers; boost agent productivity and satisfaction; a

Adobe is the global leader in digital media and digital marketing solutions. Our creative, marketing and document solutions empower everyone – from emerging artists to global brands – to bring digital creations to life and deliver immersive, compelling experiences to the right person at the right mo

At Sage, we knock down barriers with information, insights, and tools to help your business flow. We provide businesses with software and services that are simple and easy to use, as we work with you to give you that feeling of confidence. Customers trust our Payroll, HR, and Finance software to m

Xiaomi Corporation was founded in April 2010 and listed on the Main Board of the Hong Kong Stock Exchange on July 9, 2018 (1810.HK). Xiaomi is a consumer electronics and smart manufacturing company with smartphones and smart hardware connected by an IoT platform at its core. Embracing our vision
A problem isn't truly solved until it's solved for all. Googlers build products that help create opportunities for everyone, whether down the street or across the globe. Bring your insight, imagination and a healthy disregard for the impossible. Bring everything that makes you unique. Together, we c
.png)
Today's cyberthreat landscape demands more than technical expertise: it requires a unified response team of technical responders, insurers, brokers,...
Security analytics and operations management platform Securonix recently published details on a tricky new malware campaign they named...
LG Display announces that it has become the first automotive display maker to obtain cybersecurity certification, confirming its leadership...
New Hampshire - Getting 'Up To Speed' on NH's Cyber Security Threats - NH Journal - Technology.
With RIT's Cybersecurity Clinic, students are gaining real-world pentesting and vulnerability assessment experience, while also helping the...
As global dependence on digital systems deepens, cybercrime is accelerating, offering a troubling preview of what 2026 may hold.
With cybercrime on the rise, it's more important than ever to put safeguards in place to protect your practice. Here are five tips to help...
The incident damaged the OnSolve CodeRED "environment in a targeted attack by an organized cybercriminal group," officials say.
The NDAA notably deviates partly from President Donald Trump's national security strategy, which seeks some distance between the U.S. and...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of AutomatorWP is https://automatorwp.com.
According to Rankiteo, AutomatorWP’s AI-generated cybersecurity score is 749, reflecting their Moderate security posture.
According to Rankiteo, AutomatorWP currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, AutomatorWP is not certified under SOC 2 Type 1.
According to Rankiteo, AutomatorWP does not hold a SOC 2 Type 2 certification.
According to Rankiteo, AutomatorWP is not listed as GDPR compliant.
According to Rankiteo, AutomatorWP does not currently maintain PCI DSS compliance.
According to Rankiteo, AutomatorWP is not compliant with HIPAA regulations.
According to Rankiteo,AutomatorWP is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
AutomatorWP operates primarily in the Software Development industry.
AutomatorWP employs approximately 1 people worldwide.
AutomatorWP presently has no subsidiaries across any sectors.
AutomatorWP’s official LinkedIn profile has approximately 249 followers.
AutomatorWP is classified under the NAICS code 5112, which corresponds to Software Publishers.
No, AutomatorWP does not have a profile on Crunchbase.
Yes, AutomatorWP maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/automatorwp.
As of December 08, 2025, Rankiteo reports that AutomatorWP has experienced 1 cybersecurity incidents.
AutomatorWP has an estimated 27,413 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability.
Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with urgent patching..
Title: CVE-2024-13496 Vulnerability in GamiPress WordPress Plugin
Description: A critical vulnerability, CVE-2024-13496, was discovered in the GamiPress WordPress plugin, potentially impacting numerous WordPress websites using the plugin for gamification and rewards systems. An unauthenticated SQL injection flaw enabled attackers to manipulate SQL queries, posing a high risk of sensitive data extraction and website compromise. Although there was no immediate evidence of exploitation, the vulnerability, with a CVSS score of 7.5, required urgent attention and patching. The potential losses could have included customer trust erosion, unauthorized access to personal data, and a consequential threat to the websites' integrity and reputation.
Type: SQL Injection
Attack Vector: Unauthenticated SQL Injection
Vulnerability Exploited: CVE-2024-13496
Common Attack Types: The most common types of attacks the company has faced is Vulnerability.

Data Compromised: Customer trust erosion, Unauthorized access to personal data
Systems Affected: WordPress websites using GamiPress plugin
Brand Reputation Impact: threat to the websites' integrity and reputation
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Data and .

Entity Name: WordPress websites using GamiPress plugin
Entity Type: Websites
Industry: Various

Remediation Measures: urgent patching

Type of Data Compromised: Personal data
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: urgent patching.
Most Significant Data Compromised: The most significant data compromised in an incident were customer trust erosion, unauthorized access to personal data and .
Most Significant System Affected: The most significant system affected in an incident was WordPress websites using GamiPress plugin.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were unauthorized access to personal data and customer trust erosion.
.png)
A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-known/oauth-authorization-server of the component OAuth Server Discovery. Such manipulation of the argument authorizationUrl leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
A flaw has been found in code-projects Question Paper Generator up to 1.0. This vulnerability affects unknown code of the file /selectquestionuser.php. This manipulation of the argument subid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration Module. Executing manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.