CVE-2025-4520: Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4520?
CVE-2025-4520 is considered a medium severity vulnerability due to the potential for unauthorized data modification by authenticated attackers.
How do I fix CVE-2025-4520?
To fix CVE-2025-4520, update the Uncanny Automator plugin to version 6.4.0.3 or later.
Who is affected by CVE-2025-4520?
CVE-2025-4520 affects users of the Uncanny Automator plugin for WordPress versions up to and including 6.4.0.2.
What type of attacks can occur due to CVE-2025-4520?
CVE-2025-4520 allows authenticated attackers with subscriber-level permissions to modify data without proper authorization.
Is there a workaround for CVE-2025-4520?
Currently, the only recommended action for CVE-2025-4520 is to upgrade the plugin to the latest version, as no official workaround is available.