Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Uncannyowl

First CVE: Dec 23, 2020Active for: 6 yearsTotal CVEs: 27
34.8
VTI Score
Medium

Uncannyowl develops a suite of WordPress plugins centered on learning management and automation, including Uncanny Automator, Uncanny Toolkit for LearnDash, and related products that extend WordPress-based educational platforms. The vendor's vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, clustering around web-application weaknesses such as missing authorization, cross-site scripting, cross-site request forgery, deserialization flaws, and sensitive data exposure that are characteristic of plugin-based access-control and input-handling responsibilities. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Uncannyowl over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2020
5 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-2075HIGH
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6
Apr 4, 20258.840NOYES
CVE-2026-56031HIGH
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
Jun 26, 20268.131NONO
CVE-2026-65462HIGH
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
Jul 23, 20267.630NONO
CVE-2025-48133CRITICAL
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Un
Jun 5, 20259.829NONO
CVE-2024-37119CRITICAL
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automato
Nov 1, 20249.829NONO
CVE-2023-34020MEDIUM
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.
Mar 27, 20246.128NOYES
CVE-2025-3623CRITICAL
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automat
May 14, 20259.126NONO
CVE-2023-23714HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions.
May 26, 20238.825NONO
CVE-2024-37118HIGH
Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.
Jun 21, 20248.824NONO
CVE-2025-57988MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Sto
Sep 22, 20256.522NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
52%
30%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None15 (55.6%)
Unknown0 (0.0%)
Required12 (44.4%)
Privileges Required
Low8 (29.6%)
High4 (14.8%)
None15 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
7.4% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Uncannyowl.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Uncannyowl — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Uncannyowl's Products

View all 3 CNAs →

Top CWEs