Privilege Escalation Vulnerability in Uncanny Automator Plugin for WordPress
CVE-2025-2075
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 April 2025
What is CVE-2025-2075?
The Uncanny Automator plugin for WordPress is susceptible to a Privilege Escalation vulnerability affecting all versions up to 6.3.0.2. This flaw arises from the absence of necessary capability checks in the add_role() and user_role() functions when called through validate_rest_call(). An unauthenticated attacker with an active account can exploit this vulnerability to assign arbitrary user roles, such as administrator, thus gaining full access to the site. This poses a significant security risk to WordPress installations using the affected plugin.
Affected Version(s)
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin * <= 6.3.0.2
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved