Server-Side Request Forgery in Uncanny Automator Plugin for WordPress
CVE-2024-13838
3.8LOW
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 March 2025
What is CVE-2024-13838?
The Uncanny Automator plugin for WordPress is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This issue affects all versions up to and including 6.2. It arises from the 'call_webhook' method in the Automator_Send_Webhook class, which allows authenticated attackers with Administrator-level access to initiate web requests to arbitrary internal resources. This capability can be exploited to query and manipulate sensitive data from internal services, posing a significant security risk.
Affected Version(s)
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin * <= 6.2