The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
We have discovered 234 live websites that are affected by CVE-2025-4520.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 234 live websites (103.54% of Uncanny Automator install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 34 versions ( 94.44% of all versions) |
![]() | 125 websites |
![]() | 27 websites |
![]() | 7 websites |
![]() | 5 websites |
![]() | 5 websites |
![]() | 4 websites |
![]() | 4 websites |
![]() | 4 websites |
![]() | 4 websites |
.com | 106 websites |
.org | 19 websites |
.co.uk | 10 websites |
.net | 8 websites |
.ca | 6 websites |
.com.au | 5 websites |
.es | 4 websites |
.fr | 3 websites |
.de | 3 websites |
.com.br | 3 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***************.*************.gov | ![]() | *,***,*** | |
*******.******.org | ![]() | *,***,*** | |
**********.******.org | ![]() | *,***,*** | |
***************.nl | ![]() | *,***,*** | |
*****.**.gov | ![]() | *,***,*** | |
*************************.nl | ![]() | *,***,*** | |
***************.***.au | ![]() | *,***,*** | |
**********.ch | ![]() | *,***,*** | |
*************.ch | ![]() | *,***,*** | |
*************.******.org | ![]() | *,***,*** | |
*********.******.org | ![]() | *,***,*** | |
*********.li | ![]() | *,***,*** | |
********.*************.gov | ![]() | *,***,*** | |
******.***.ar | ![]() | *,***,*** | |
*************.****************.com | ![]() | *,***,*** | |
*********.swiss | ![]() | *,***,*** | |
******.ua | ![]() | *,***,*** | |
**************.***.au | ![]() | *,***,*** | |
**************.***.au | ![]() | **,***,*** | |
*******************.ch | ![]() | **,***,*** |
FAQ