SecAlerts
u

uncannyowl

Security Risk Profile

53
/100
medium

Security Risk Score

Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 23, 2020 to present

15
Total CVEs
8
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
53/100
medium

Severity Distribution

Critical
3
High
5
Medium
6
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
CSRF
2
3
SSRF
1
4
Infoleak
1

Most Affected Products

1. Uncannyowl Uncanny Automator Wordpress9
2. Uncanny Automator Uncanny Automator3
3. Uncanny Owl Uncanny Automator Pro2
4. Uncannyowl Uncanny Groups For Learndash Wordpress2
5. Uncannyowl Uncanny Toolkit For Learndash Wordpress2

Recent Vulnerabilities

See more →
CVE-2025-48133
CVSS 9.8EPSS 0%critical

WordPress Uncanny Automator plugin <= 6.4.0.2 - Broken Access Control Vulnerability

Jun 5, 2025
CVE-2025-4520
CVSS 5.4EPSS 0%medium

Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update

May 14, 2025🔧 No Patch
CVE-2025-3623
CVSS 9.1critical

Uncanny Automator <= 6.4.0.1 - Unauthenticated PHP Object Injection in automator_api_decode_message Function

May 14, 2025
CVE-2025-2075
CVSS 8.8high

Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

Apr 4, 2025
CVE-2024-13838
CVSS 5.5medium

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook

Mar 12, 2025
CVE-2024-37119
CVSS 9.8critical

WordPress Uncanny Automator Pro plugin < 5.3.0.1 - Unauthenticated License Settings Reset vulnerability

Nov 1, 2024
CVE-2024-8350
CVSS 2.7EPSS 0%low

Uncanny Groups for LearnDash <= 6.1.0.1 - Missing Authorization to Authenticated (Group Leader+) User Group Add

Sep 25, 2024🔧 No Patch
CVE-2024-8349
CVSS 7.2EPSS 0%high

Uncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation

Sep 25, 2024🔧 No Patch
CVE-2024-37117
CVSS 7.1high

WordPress Uncanny Automator Pro plugin <= 5.3 - Reflected Cross Site Scripting (XSS) vulnerability

Jul 22, 2024
CVE-2024-37118
CVSS 8.8high

WordPress Uncanny Automator Pro plugin <= 5.3 - Cross Site Request Forgery (CSRF) Leading to License Settings Reset vulnerability

Jun 21, 2024🔧 No Patch

Monitor uncannyowl in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

uncannyowl Security Vulnerabilities & Risk Score | 15 CVEs | SecAlerts - SecAlerts