Uncanny Automator – Automate everything with the #1 automation, integration & webhooks plugin, ddf5f9d86afbe75cbc375e6b9fccd93807fbf75c
- CVE, Research URL
- Home page URL
- Application
-
Uncanny Automator – Automate everything with the #1 automation, integration & webhooks plugin
- Published on
- May 24, 2023
- Research Description
- Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 4.15 Uncanny Automator <= 4.14 - Cross-Site Request Forgery via update_automator_connect The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.14. This is due to missing or incorrect nonce validation on the update_automator_connect function. This makes it possible for unauthenticated attackers to perform certain tasks in the setup wizard via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 4.15.
- Status
-
vulnerable