cleantalk
Vulnerabilities and Security Researches

Uncanny Automator – Automate everything with the #1 automation, integration & webhooks plugin, ddf5f9d86afbe75cbc375e6b9fccd93807fbf75c

Published on
May 24, 2023
Research Description
Uncanny Automator &#8211; Easy Automation, Integration, Webhooks &amp; Workflow Builder Plugin [uncanny-automator] < 4.15 Uncanny Automator <= 4.14 - Cross-Site Request Forgery via update_automator_connect The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.14. This is due to missing or incorrect nonce validation on the update_automator_connect function. This makes it possible for unauthenticated attackers to perform certain tasks in the setup wizard via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 4.15.
Status
vulnerable