Uncanny Automator has issued a security incident notice after discovering unauthorized access involving a third-party service used by the company. The disclosure comes just days after Sansec researchers discovered an active supply chain attack hitting WordPress sites running OptinMonster, TrustPulse, PushEngage, and MonsterInsights website was compromised taking the tally of affected Awesome Motive plugins to five.
Uncanny Automator Reports Unauthorized Access
In a notice published on its website, the Uncanny Automator team said that on June 12, 2026, an attacker had exploited a vulnerability in third-party software running on automatorplugin.com and gained access to part of its infrastructure. The attacker’s access was removed on June 13, 2026.
According to the Security Incident Notice published on June 15, the attacker gained access to customer account information and altered the packaged plugin distributed through the update server causing licensed sites checking for updates to briefly receive a backdoored version labeled 7.3.0.5.
The company clarified that the compromise affected only the distributed package on the update infrastructure and did not involve its plugin source code repository. It also emphasized that passwords, payment information, WordPress administrator credentials, and API keys were not exposed during the incident.
On the same day the company also send out email warning about phishing emails: “Because your name and email address were taken, you may receive convincing phishing emails that reference real information about your account — for example, urging you to “update” Uncanny Automator by clicking a link or downloading a file. Legitimate updates are delivered only through your WordPress dashboard, your account area at automatorplugin.com, or WordPress.org.”
The company also directly contacted the website owners who had downloaded the affected version 7.3.0.5. The team also warned, “A site that installed 7.3.0.5 should be treated as fully compromised; it is not resolved by an in-place update and requires the full remediation steps sent to affected users.”
OptinMonster, TrustPulse, and PushEngage Face Supply Chain Attack
On June 13, Sansec researchers disclosed an active supply chain attack affecting Awesome Motive plugins OptinMonster, TrustPulse, and PushEngage. The attackers had injected malicious JavaScript into legitimate files distributed through Awesome Motive’s CDN infrastructure, exposing more than one million WordPress sites to the compromised code.
OptinMonster’s Security Incident report confirmed Sansec’s findings. The company stated that an attacker had obtained credentials for its content delivery network (CDN) and used them to distribute a tampered version of the JavaScript files served by the affected products. “For a limited window, sites that embed our script loaded this modified file directly from our CDN,” the notice said.
The company also shared the scope of the breach. According to the report, its application servers, source code repositories, and systems storing OptinMonster and TrustPulse account information were hosted separately and were not compromised. It added: “We have no evidence that account data or personal details held by us were accessed. The compromise was limited to our marketing website server and, through a CDN API key stored on it, our CDN account.”
Further investigation revealed that the attacker exploited a critical unauthenticated authentication bypass vulnerability in the UpdraftPlus plugin, tracked as CVE-2026-10795. The flaw, which carried a CVSS score of 8.1, had been patched on June 5, 2026. By leveraging the vulnerability, the attacker gained access to the server hosting OptinMonster’s marketing website and modified the files distributed through its CDN. Wordfence had awarded a $5,200 bounty to the researcher who discovered and responsibly disclosed the vulnerability.
The company assured that they have “remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key.” The security incident report also reveals that the attack could only have impacted sites that loaded the affected script with an administrator logged in during June 12, 2026 (UTC).
Patchstack’s Security Research Lead, Dave Jong, also shared their findings on the attack. According to Jong, the campaign did not exploit a plugin vulnerability in the traditional sense. The malicious JavaScript ran in the browsers of logged-in administrators who viewed the affected pages. It used their active sessions to secretly create fake administrator accounts and install a hidden backdoor plugin without the site owners noticing.
“Because the payload runs client-side with valid credentials and a valid nonce, every malicious request looks, at the network layer, almost exactly like a real administrator adding a user,” Jong explained. “That is what makes this campaign interesting, and what made it tricky to stop without breaking legitimate functionality.”
MonsterInsights Website Compromised
On June 13, MonsterInsights website was hacked and several customers received phishing emails asking them to download Version 10.3.0.

The website was later restored.
Scope of the Attacks
The scale of these incidents becomes even more staggering when viewed through the lens of the affected plugins’ reach. According to WordPress plugin repository, MonsterInsights is installed on more than 2 million websites, OptinMonster powers over 1 million sites, Uncanny Automator has more than 40,000 active installations, and PushEngage is used on over 9,000 websites.
Also Awesome Motive’s portfolio includes several significantly larger and more widely adopted plugins, such as WPForms, which has over 5 million active installations. As of now, there have been no reported security breaches affecting those products. However, if a similar incident were to impact one of these higher-adoption plugins, the potential impact and scale of exposure would be substantially greater due to their much larger user base.