Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
high
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_c...
- CVSS:
- 7.5
- Affected:
- up to 7.3.2
- Fixed in:
- 7.4.0
- Disclosed:
- Jul 27, 2026
CVE-2026-15025 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.3.2 - Authenticated (Administrator+) SQL Injection
medium
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...
- CVSS:
- 4.9
- Affected:
- up to 7.3.2
- Fixed in:
- 7.4.0
- Disclosed:
- Jul 22, 2026
CVE-2026-65462 on NVD →
Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token
high
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to...
- CVSS:
- 8.1
- Affected:
- up to 7.3.1.4
- Fixed in:
- 7.4.0
- Disclosed:
- Jul 15, 2026
CVE-2026-15008 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.3.1.2 - Unauthenticated PHP Object Injection
high
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.3.1.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP...
- CVSS:
- 8.1
- Affected:
- up to 7.3.1.2
- Fixed in:
- 7.3.1.3
- Disclosed:
- Jun 23, 2026
CVE-2026-56031 on NVD →
Uncanny Automator - WordPress Uncanny Automator - Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload vulnerability
high
WordPress Uncanny Automator - Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload vulnerability
- CVSS:
- 7.2
- Affected:
- up to 7.0.0.3
- Fixed in:
- 7.1.0
- Disclosed:
- Mar 2, 2026
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload
high
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access an...
- CVSS:
- 7.2
- Affected:
- up to 7.0.0.3
- Fixed in:
- 7.1.0
- Disclosed:
- Mar 2, 2026
CVE-2026-2269 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 7.0.0
unknown
[en] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on th...
- Affected:
- up to 7.0.0
- Fixed in:
- 7.0.0
- Disclosed:
- Jan 23, 2026
CVE-2025-15522 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on the ver...
- CVSS:
- 6.4
- Affected:
- up to 6.10.0.2
- Fixed in:
- 7.0.0
- Disclosed:
- Jan 22, 2026
CVE-2025-15522 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.10.0
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.
- Affected:
- up to 6.10.0
- Fixed in:
- 6.10.0
- Disclosed:
- Nov 21, 2025
CVE-2025-66056 on NVD →
Uncanny Automator < 6.10.0 - Authenticated (Subscriber+) Information Exposure
medium
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 6.10.0 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or...
- CVSS:
- 4.3
- Affected:
- up to 6.10.0
- Fixed in:
- 6.10.0
- Disclosed:
- Nov 7, 2025
CVE-2025-66056 on NVD →
Uncanny Automator <= 6.7.0.1 - Missing Authorization
medium
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.7.0.1. This makes it possible for authenticated attackers, with Subscriber-level acce...
- CVSS:
- 4.3
- Affected:
- up to 6.7.0.1
- Fixed in:
- 6.8.0
- Disclosed:
- Aug 27, 2025
CVE-2025-58193 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.8.0
unknown
[en] Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Uncanny Automator: from n/a through 6.7.0.1.
- Affected:
- up to 6.8.0
- Fixed in:
- 6.8.0
- Disclosed:
- Aug 27, 2025
CVE-2025-58193 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.5.0
unknown
[en] Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through 6.4.0.2.
- Affected:
- up to 6.5.0
- Fixed in:
- 6.5.0
- Disclosed:
- Jun 5, 2025
CVE-2025-48133 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.4.0.2 - Missing Authorization
medium
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.4.0.2. This makes it possible for unauthenticated attackers to perform an unauthorize...
- CVSS:
- 6.5
- Affected:
- up to 6.4.0.2
- Fixed in:
- 6.5.0
- Disclosed:
- Jun 2, 2025
CVE-2025-48133 on NVD →
Uncanny Automator <= 6.4.0.1 - Unauthenticated PHP Object Injection in automator_api_decode_message Function
critical
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain...
- CVSS:
- 9.1
- Affected:
- up to 6.4.0.1
- Fixed in:
- 6.4.0.2
- Disclosed:
- May 13, 2025
CVE-2025-3623 on NVD →
Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
medium
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
- CVSS:
- 5.4
- Affected:
- up to 6.4.0.2
- Fixed in:
- 6.5.0
- Disclosed:
- May 9, 2025
CVE-2025-4520 on NVD →
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
high
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call() func...
- CVSS:
- 8.8
- Affected:
- up to 6.3.0.2
- Fixed in:
- 6.4.0
- Disclosed:
- Apr 3, 2025
CVE-2025-2075 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.3
unknown
[en] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers,...
- Affected:
- up to 6.3
- Fixed in:
- 6.3
- Disclosed:
- Mar 12, 2025
CVE-2024-13838 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook
medium
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers, with...
- CVSS:
- 5.5
- Affected:
- up to 6.2
- Fixed in:
- 6.3
- Disclosed:
- Mar 11, 2025
CVE-2024-13838 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 5.1.0.3
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin:...
- Affected:
- up to 5.1.0.3
- Fixed in:
- 5.1.0.3
- Disclosed:
- Jan 5, 2024
CVE-2023-52151 on NVD →
Uncanny Automator <= 5.1.0.2 - Sensitive Information Exposure via Log File
medium
The Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0.2 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data i...
- CVSS:
- 5.3
- Affected:
- up to 5.1.0.2
- Fixed in:
- 5.1.0.3
- Disclosed:
- Dec 28, 2023
CVE-2023-52151 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 4.15
unknown
Update the WordPress Uncanny Automator plugin to the latest available version (at least 4.15).
WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Uncanny Automator Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions und...
- Affected:
- up to 4.15
- Fixed in:
- 4.15
- Disclosed:
- May 25, 2023
Uncanny Automator <= 4.14 - Cross-Site Request Forgery via update_automator_connect
medium
The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.14. This is due to missing or incorrect nonce validation on the update_automator_connect function. This makes it possible for unauthenticated attackers to perform certain tasks in the setup wizard...
- CVSS:
- 5.4
- Affected:
- up to 4.15
- Fixed in:
- 4.15
- Disclosed:
- May 24, 2023
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 4.15
unknown
The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.14. This is due to missing or incorrect nonce validation on the update_automator_connect function. This makes it possible for unauthenticated attackers to perform certain tasks in the setup wizard...
- Affected:
- up to 4.15
- Fixed in:
- 4.15
- Disclosed:
- May 24, 2023
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.5.0
unknown
- Affected:
- up to 6.5.0
- Fixed in:
- 6.5.0
CVE-2025-4520 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.4.0.2
unknown
- Affected:
- up to 6.4.0.2
- Fixed in:
- 6.4.0.2
CVE-2025-3623 on NVD →
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 6.4.0
unknown
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
CVE-2025-2075 on NVD →