Uncannyowl develops a suite of WordPress plugins centered on learning management and automation, including Uncanny Automator, Uncanny Toolkit for LearnDash, and related products that extend WordPress-based educational platforms. The vendor's vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, clustering around web-application weaknesses such as missing authorization, cross-site scripting, cross-site request forgery, deserialization flaws, and sensitive data exposure that are characteristic of plugin-based access-control and input-handling responsibilities. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uncannyowl over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2075HIGH The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6 | Apr 4, 2025 | 8.8 | 40 | NO | YES |
CVE-2026-56031HIGH Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. | Jun 26, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-65462HIGH Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | Jul 23, 2026 | 7.6 | 30 | NO | NO |
CVE-2025-48133CRITICAL Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Un | Jun 5, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-37119CRITICAL Missing Authorization vulnerability in Uncanny Owl Uncanny Automator Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automato | Nov 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-34020MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3. | Mar 27, 2024 | 6.1 | 28 | NO | YES |
CVE-2025-3623CRITICAL The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automat | May 14, 2025 | 9.1 | 26 | NO | NO |
CVE-2023-23714HIGH Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions. | May 26, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-37118HIGH Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3. | Jun 21, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-57988MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Sto | Sep 22, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uncannyowl.
Media articles that mention a CVE ID that affects a product developed by Uncannyowl — matched by CVE ID, not by vendor name.