Record summary

CVE-2025-2075 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call() function. This makes it possible for unauthenticated attackers to set the role of arbitrary users to administrator granting full access to the site, though privilege escalation requires an active account on the site so this is considered an authenticated privilege escalation.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 4, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 4, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Browse uncannyowl / Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

Default status: unaffected

CVE ListThrough 6.3.0.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHUncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationCVSS 8.8

The Uncanny Automator - Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call() function. This makes it possible for unauthenticated attackers to set the role of arbitrary users to administrator granting full access to the site, though privilege escalation requires an active account on the site so this is considered an authenticated privilege escalation.

Impact

Authenticated attackers with subscriber-level access can escalate their privileges to administrator through missing capability checks, gaining full control over the WordPress site.

Remediation

Update to version 6.4.0 or later to remediate this vulnerability.

WeaknessesCWE-862
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2025wordpresswp-pluginauthenticatedwpuncanny-automatorvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
FOFA: body="/wp-content/plugins/uncanny-automator/"

Source: ProjectDiscovery

References

4