WordPress Plugin Vulnerabilities

Uncanny Automator < 6.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update

Description

The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.

Affects Plugins

Fixed in 6.5.0

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
mikemyers
Verified
No

Timeline

Publicly Published
2025-05-09 (about 1 year ago)
Added
2025-05-13 (about 1 year ago)
Last Updated
2025-05-14 (about 1 year ago)

Other