Uncanny Automator
cpe:2.3:a:uncannyowl:uncanny_automator:*:*:*:*:wordpress:*:*
- <= 6.4.0.2
A vulnerability exists in the Uncanny Automator WordPress plugin, in versions through 6.4.0.2, allowing authenticated users with subscriber-level permissions or higher to unauthorizedly modify plugin settings. This issue arises from a lack of proper capability checks on several AJAX functions, which could be exploited to update plugin configurations without the necessary permissions.
Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing for further exploitation or disruption of site functionality.
Users are advised to update the Uncanny Automator WordPress plugin to version 6.5.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.