Description
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
Problem types
Product status
Any version
Timeline
| 2025-04-21: | Discovered |
| 2025-04-21: | Vendor Notified |
| 2025-05-09: | Disclosed |
Credits
Michael Mazzolini
References
www.wordfence.com/...-67b5-4103-93b0-682200199a71?source=cve
plugins.trac.wordpress.org/.../keap/helpers/keap-helpers.php