CVE-2025-3623 – WordPress Uncanny Automator PHP Object Injection Vulnerability

CVE ID : CVE-2025-3623

Published : May 14, 2025, 3:15 a.m. | 50 minutes ago

Description : The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

نوشته های مشابه