← WordPress Vulnerabilities
WordPress security by component

Uncanny Automator

Uncanny Automator is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.1.

Plugin slug: uncanny-automator

CVE-2026-65462: Uncanny Automator: SQL injection

Uncanny Automator is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.3.2.

PublishedJul 23, 2026
Known safe version7.4.0
Safe version
Jul 23, 2026 CVE-2026-65462
Uncanny Automator: SQL injection
Uncanny Automator is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.3.2.
7.4.0
CVE7.6
NVDPending
Jul 16, 2026 CVE-2026-15008
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: Code execution
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 7.3.1.4.
> 7.3.1.4
CVE8.1
NVDPending
Jun 26, 2026 CVE-2026-56031
Uncanny Automator: Code execution
Uncanny Automator is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 7.3.1.2.
7.3.1.3
CVE8.1
NVDPending
Jan 23, 2026 CVE-2025-15522
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: Cross-site scripting
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 21, 2025 CVE-2025-66056
Uncanny Automator: A security weakness
Uncanny Automator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 27, 2025 CVE-2025-58193
Uncanny Automator: A security weakness
Uncanny Automator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 05, 2025 CVE-2025-48133
Uncanny Automator: A security weakness
Uncanny Automator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD9.8
May 14, 2025 CVE-2025-4520
Uncanny Automator: A security weakness
Uncanny Automator is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
May 14, 2025 CVE-2025-3623
Uncanny Automator: Code execution
Uncanny Automator is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.1
NVDPending
Apr 04, 2025 CVE-2025-2075
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder: Privilege escalation or authentication bypass
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Mar 12, 2025 CVE-2024-13838
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: Server-side request forgery
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.5
NVD3.8
Jan 05, 2024 CVE-2023-52151
Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: A security weakness
Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3