WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included

The AI + Automation platform for WordPress. Automate workflows across all your plugins and apps, add an AI agent, and build pages with AI — no code.

15Reported vulnerabilities
9.1Highest CVSS score
7.5.1.1Latest version
40,000+Active installs

What to do now

Update Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included to 7.4.0 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 15, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-2075 High 8.8 2.7% Before 6.4 6.4 April 4, 2025
CVE-2025-3623 Critical 9.1 0.8% Before 6.4.0.2 6.4.0.2 May 14, 2025
CVE-2026-15008 High 8.1 1.0% 0 to 7.3.1.4 (inclusive) 7.4.0 July 16, 2026
CVE-2026-56031 High 8.1 0.4% 7.3.1.2 and earlier 7.3.1.3 June 23, 2026
CVE-2026-15025 High 7.5 0.5% 0 to 7.3.2 (inclusive) 7.4.0 July 28, 2026
CVE-2026-2269 High 7.2 0.7% 7.0.0.3 and earlier 7.1.0 March 2, 2026
CVE-2025-15522 Medium 6.4 0.3% 0 to 6.10.0.2 (inclusive) 7.0.0 January 23, 2026
CVE-2025-48133 Medium 6.5 0.3% 6.4.0.2 and earlier 6.5.0 June 2, 2025
CVE-2023-52151 Medium 5.3 0.4% 5.1.0.2 and earlier 5.1.0.3 December 28, 2023
WF-bd0d8661-4725-41dd-88ce-8e94e285d5b8 Medium 5.4 Before 4.15 4.15 May 24, 2023
CVE-2026-65462 Medium 4.9 0.4% 7.3.2 and earlier 7.4.0 July 22, 2026
CVE-2025-66056 Medium 4.3 0.3% Before 6.10.0 6.10.0 November 7, 2025
CVE-2025-58193 Medium 4.3 0.2% 6.7.0.1 and earlier 6.8.0 August 27, 2025
CVE-2025-4520 Medium 4.3 0.3% Before 6.5.0 6.5.0 May 14, 2025
CVE-2024-13838 Low 3.8 0.3% Before 6.3 6.3 March 12, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.