Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Uncanny Automator: from n/a through 6.7.0.1.
Fixes

Solution

Update the WordPress Uncanny Automator plugin to the latest available version (at least 6.8.0).


Workaround

No workaround given by the vendor.

History

Thu, 28 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Uncannyowl
Uncannyowl uncanny Automator
Wordpress
Wordpress wordpress
Vendors & Products Uncannyowl
Uncannyowl uncanny Automator
Wordpress
Wordpress wordpress

Wed, 27 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 18:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Uncanny Automator: from n/a through 6.7.0.1.
Title WordPress Uncanny Automator Plugin <= 6.7.0.1 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-08-27T18:53:40.989Z

Reserved: 2025-08-27T16:18:58.323Z

Link: CVE-2025-58193

cve-icon Vulnrichment

Updated: 2025-08-27T18:26:10.354Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-27T18:15:46.697

Modified: 2025-08-29T16:24:09.860

Link: CVE-2025-58193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-28T07:40:54Z