CVE-2025-3623
- EPSS 0.83%
- Veröffentlicht 14.05.2025 02:23:17
- Zuletzt bearbeitet 12.08.2025 01:51:52
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthent...
CVE-2025-2075
- EPSS 2.47%
- Veröffentlicht 04.04.2025 04:21:22
- Zuletzt bearbeitet 08.08.2025 20:07:37
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing pr...
CVE-2024-13838
- EPSS 0.29%
- Veröffentlicht 12.03.2025 07:00:22
- Zuletzt bearbeitet 02.04.2025 12:41:07
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_W...
CVE-2024-37119
- EPSS 0.55%
- Veröffentlicht 01.11.2024 15:15:19
- Zuletzt bearbeitet 11.08.2025 14:34:43
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator Pro: from n/a through 5.3.0.0.
CVE-2024-37117
- EPSS 0.33%
- Veröffentlicht 22.07.2024 10:15:05
- Zuletzt bearbeitet 21.11.2024 09:23:13
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3.
CVE-2024-37118
- EPSS 0.2%
- Veröffentlicht 21.06.2024 14:15:12
- Zuletzt bearbeitet 26.03.2025 14:15:31
Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.
CVE-2023-52151
- EPSS 0.44%
- Veröffentlicht 05.01.2024 11:15:11
- Zuletzt bearbeitet 28.04.2026 19:23:00
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate e...