CVE-2026-15025
- EPSS 0.51%
- Veröffentlicht 28.07.2026 11:32:46
- Zuletzt bearbeitet 28.07.2026 16:07:15
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_seg...
CVE-2026-65462
- EPSS 0.28%
- Veröffentlicht 23.07.2026 11:18:40
- Zuletzt bearbeitet 23.07.2026 15:17:58
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
CVE-2026-15008
- EPSS 0.59%
- Veröffentlicht 16.07.2026 07:51:04
- Zuletzt bearbeitet 17.07.2026 13:17:57
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and includ...
CVE-2026-56031
- EPSS 0.31%
- Veröffentlicht 26.06.2026 14:52:34
- Zuletzt bearbeitet 26.06.2026 18:17:01
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
CVE-2026-2269
- EPSS 0.66%
- Veröffentlicht 03.03.2026 02:16:10
- Zuletzt bearbeitet 22.04.2026 21:26:58
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it po...
CVE-2025-15522
- EPSS 0.26%
- Veröffentlicht 23.01.2026 04:34:58
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2...
CVE-2025-66056
- EPSS 0.26%
- Veröffentlicht 21.11.2025 12:29:54
- Zuletzt bearbeitet 15.04.2026 00:35:42
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.
CVE-2025-58193
- EPSS 0.19%
- Veröffentlicht 27.08.2025 17:45:39
- Zuletzt bearbeitet 23.04.2026 15:33:16
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.7.0.1.
CVE-2025-48133
- EPSS 0.26%
- Veröffentlicht 05.06.2025 20:49:14
- Zuletzt bearbeitet 23.04.2026 15:30:51
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.4.0.2.
CVE-2025-4520
- EPSS 0.28%
- Veröffentlicht 14.05.2025 02:23:17
- Zuletzt bearbeitet 12.08.2025 01:55:05
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, ...