| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-2269 | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | High | 7.2 | 2026-03-03 01:21:51 | Deep Dive |
| CVE-2025-15522 | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Medium | 6.4 | 2026-01-23 04:34:58 | Deep Dive |
| CVE-2025-66056 | WordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerability | Uncanny Owl | Uncanny Automator | 中危 | - | 2025-11-21 12:29:54 | Deep Dive |
| CVE-2025-58193 | WordPress Uncanny Automator Plugin <= 6.7.0.1 - Broken Access Control Vulnerability | Uncanny Owl | Uncanny Automator | Medium | 4.3 | 2025-08-27 17:45:39 | Deep Dive |
| CVE-2025-48133 | WordPress Uncanny Automator plugin <= 6.4.0.2 - Broken Access Control Vulnerability | Uncanny Owl | Uncanny Automator | Medium | 6.5 | 2025-06-05 20:49:14 | Deep Dive |
| CVE-2025-4520 | Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Medium | 5.4 | 2025-05-14 02:23:18 | Deep Dive |
| CVE-2025-3623 | Uncanny Automator <= 6.4.0.1 - Unauthenticated PHP Object Injection in automator_api_decode_message Function | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Critical | 9.1 | 2025-05-14 02:23:17 | Deep Dive |
| CVE-2025-2075 | Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | High | 8.8 | 2025-04-04 04:21:22 | Deep Dive |
| CVE-2024-13838 | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Medium | 5.5 | 2025-03-12 07:00:22 | Deep Dive |
| CVE-2024-37119 | WordPress Uncanny Automator Pro plugin < 5.3.0.1 - Unauthenticated License Settings Reset vulnerability | Uncanny Owl | Uncanny Automator Pro | Medium | 5.3 | 2024-11-01 14:18:37 | Deep Dive |
| CVE-2024-37117 | WordPress Uncanny Automator Pro plugin <= 5.3 - Reflected Cross Site Scripting (XSS) vulnerability | Uncanny Owl | Uncanny Automator Pro | High | 7.1 | 2024-07-22 09:40:21 | Deep Dive |
| CVE-2024-37118 | WordPress Uncanny Automator Pro plugin <= 5.3 - Cross Site Request Forgery (CSRF) Leading to License Settings Reset vulnerability | Uncanny Owl | Uncanny Automator Pro | Medium | 5.4 | 2024-06-21 13:47:58 | Deep Dive |
| CVE-2023-52151 | WordPress Uncanny Automator Plugin <= 5.1.0.2 is vulnerable to Sensitive Data Exposure | Uncanny Automator, Uncanny Owl | Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin | Medium | 5.3 | 2024-01-05 10:52:27 | Deep Dive |