Extension WordPress
Vulnérabilités Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
Cette page rassemble les failles publiées pour Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
13 fiches
Uncanny Automator <= 7.3.1.4 – Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including,…
*-7.3.1.4
7.4.0
15/07/2026
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.3.1.2 – Unauthenticated PHP Object Injection
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.3.1.2 via deserialization of untrusted input. This makes it possible for…
*-7.3.1.2
7.3.1.3
23/06/2026
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 – Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for…
*-7.0.0.3
7.1.0
02/03/2026
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization…
*-6.10.0.2
7.0.0
22/01/2026
Uncanny Automator < 6.10.0 – Authenticated (Subscriber+) Information Exposure
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 6.10.0 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access…
[*, 6.10.0)
6.10.0
07/11/2025
Uncanny Automator <= 6.7.0.1 – Missing Authorization
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.7.0.1. This…
*-6.7.0.1
6.8.0
27/08/2025
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.4.0.2 – Missing Authorization
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.4.0.2. This…
*-6.4.0.2
6.5.0
02/06/2025
Uncanny Automator <= 6.4.0.1 – Unauthenticated PHP Object Injection in automator_api_decode_message Function
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a…
*-6.4.0.1
6.4.0.2
13/05/2025
Uncanny Automator <= 6.4.0.2 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with…
*-6.4.0.2
6.5.0
09/05/2025
Uncanny Automator <= 6.3.0.2 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability…
*-6.3.0.2
6.4.0
03/04/2025
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 – Authenticated (Admin+) Server-Side Request Forgery via Webhook
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This…
*-6.2
6.3
11/03/2025
Uncanny Automator <= 5.1.0.2 – Sensitive Information Exposure via Log File
The Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0.2 via the plugin's log file. This makes…
*-5.1.0.2
5.1.0.3
28/12/2023
Uncanny Automator <= 4.14 – Cross-Site Request Forgery via update_automator_connect
The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.14. This is due to missing or incorrect nonce validation on the update_automator_connect function. This makes it possible for unauthenticated…
[*, 4.15)
4.15
24/05/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.