Extension WordPress

Vulnérabilités Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Cette page rassemble les failles publiées pour Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
1Critiques
13Avec correctif
9,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

13 fiches

CVE-2026-15008 Élevée · 8,1
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 7.3.1.4 – Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including,…

Versions affectées

*-7.3.1.4

Correctif

7.4.0

Publication

15/07/2026

CVE-2026-56031 Élevée · 8,1
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.3.1.2 – Unauthenticated PHP Object Injection

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.3.1.2 via deserialization of untrusted input. This makes it possible for…

Versions affectées

*-7.3.1.2

Correctif

7.3.1.3

Publication

23/06/2026

CVE-2026-2269 Élevée · 7,2
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 – Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for…

Versions affectées

*-7.0.0.3

Correctif

7.1.0

Publication

02/03/2026

CVE-2025-15522 Moyenne · 6,4
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization…

Versions affectées

*-6.10.0.2

Correctif

7.0.0

Publication

22/01/2026

CVE-2025-66056 Moyenne · 4,3
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator < 6.10.0 – Authenticated (Subscriber+) Information Exposure

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 6.10.0 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access…

Versions affectées

[*, 6.10.0)

Correctif

6.10.0

Publication

07/11/2025

CVE-2025-58193 Moyenne · 4,3
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 6.7.0.1 – Missing Authorization

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.7.0.1. This…

Versions affectées

*-6.7.0.1

Correctif

6.8.0

Publication

27/08/2025

CVE-2025-48133 Moyenne · 6,5
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.4.0.2 – Missing Authorization

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.4.0.2. This…

Versions affectées

*-6.4.0.2

Correctif

6.5.0

Publication

02/06/2025

CVE-2025-3623 Critique · 9,1
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 6.4.0.1 – Unauthenticated PHP Object Injection in automator_api_decode_message Function

The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a…

Versions affectées

*-6.4.0.1

Correctif

6.4.0.2

Publication

13/05/2025

CVE-2025-4520 Moyenne · 5,4
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 6.4.0.2 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update

The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with…

Versions affectées

*-6.4.0.2

Correctif

6.5.0

Publication

09/05/2025

CVE-2025-2075 Élevée · 8,8
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 6.3.0.2 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability…

Versions affectées

*-6.3.0.2

Correctif

6.4.0

Publication

03/04/2025

CVE-2024-13838 Moyenne · 5,5
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 – Authenticated (Admin+) Server-Side Request Forgery via Webhook

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This…

Versions affectées

*-6.2

Correctif

6.3

Publication

11/03/2025

CVE-2023-52151 Moyenne · 5,3
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 5.1.0.2 – Sensitive Information Exposure via Log File

The Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0.2 via the plugin's log file. This makes…

Versions affectées

*-5.1.0.2

Correctif

5.1.0.3

Publication

28/12/2023

Vulnérabilité Moyenne · 5,4
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Uncanny Automator <= 4.14 – Cross-Site Request Forgery via update_automator_connect

The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.14. This is due to missing or incorrect nonce validation on the update_automator_connect function. This makes it possible for unauthenticated…

Versions affectées

[*, 4.15)

Correctif

4.15

Publication

24/05/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités