CVE-2025-48133: WordPress Uncanny Automator plugin <= 6.4.0.2 - Broken Access Control Vulnerability
Published Jun 5, 2025
·Updated
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.4.0.2.
Affected Software
3 affected components
Uncanny Owl Uncanny Automator<=6.4.0.2
WordPress Uncanny Automator<=6.4.0.2
Uncannyowl Uncanny Automator Wordpress<6.5.0
Remediation
Information
Update the WordPress Uncanny Automator plugin to the latest available version (at least 6.5.0).
Event History
Jun 5, 2025
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48133?
CVE-2025-48133 has been classified as a high-severity vulnerability due to missing authorization controls.
2
How do I fix CVE-2025-48133?
To fix CVE-2025-48133, update the Uncanny Automator plugin to version 6.4.0.3 or later.
3
What versions are affected by CVE-2025-48133?
CVE-2025-48133 affects Uncanny Automator versions up to and including 6.4.0.2.
4
Can CVE-2025-48133 be exploited remotely?
Yes, CVE-2025-48133 can be exploited remotely due to its nature of missing access controls.
5
What impact does CVE-2025-48133 have on my website?
Exploiting CVE-2025-48133 may allow unauthorized access to sensitive actions within the Uncanny Automator plugin.