CVE-2025-4520

Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update

The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.


We have discovered 234 live websites that are affected by CVE-2025-4520.

Run a Free Instant Scan




Affected Software

Product  Uncanny Automator
Category Wordpress Plugins
Vulnerable Domains234 live websites (103.54% of Uncanny Automator install base)
Vulnerable Versions
  • from 0 through 6.4.0.2
Vulnerable Versions Count34 versions ( 94.44% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - May 14, 2025
  • Updated - May 14, 2025

Credits

  • Michael Mazzolini (finder)

CVE-2025-4520 usage by Country

United States125 websites



Germany27 websites
GB7 websites
Cyprus5 websites
France5 websites
Denmark4 websites
Australia4 websites
South Africa4 websites
Spain4 websites

CVE-2025-4520 usage by TLD

.com106 websites
.org19 websites
.co.uk10 websites
.net8 websites
.ca6 websites
.com.au5 websites
.es4 websites
.fr3 websites
.de3 websites
.com.br3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-4520

Top websites that are affected by CVE-2025-4520. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.*************.gov United States*,***,***
*******.******.org United States*,***,***
**********.******.org United States*,***,***
***************.nl United States*,***,***
*****.**.gov United States*,***,***
*************************.nl United States*,***,***
***************.***.au United States*,***,***
**********.ch United States*,***,***
*************.ch United States*,***,***
*************.******.org United States*,***,***
*********.******.org United States*,***,***
*********.li Liechtenstein*,***,***
********.*************.gov United States*,***,***
******.***.ar United States*,***,***
*************.****************.com United States*,***,***
*********.swiss United States*,***,***
******.ua United States*,***,***
**************.***.au Australia*,***,***
**************.***.au United States**,***,***
*******************.ch Switzerland**,***,***
See full domain list

FAQ

CVE-2025-4520 is Missing Authorization in Uncanny Automator
A total of 234 websites have been identified as vulnerable to CVE-2025-4520, based on global website indexing conducted by WebTechSurvey.
The Uncanny Automator is affected by the CVE-2025-4520 vulnerability.
Uncanny Automator versions up to and including 6.4.0.2 are vulnerable to CVE-2025-4520.