CVE-2025-2075

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 862

Summary

CVE-2025-2075 is a privilege escalation vulnerability affecting the Uncanny Automator plugin for WordPress, which is used for automation, integration, webhooks, and workflow building. The issue lies in the lack of capable checks performed by the add_role() and user_role() functions through the validate_rest_call() function. This vulnerability allows unauthenticated attackers to grant themselves administrator access to the site if they already have an account, making it an authenticated privilege escalation. Versions up to and including 6.3.0.2 are impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share