Junglewise Threat Intelligence

CVE-2026-65462: Uncanny Owl Uncanny Automator SQL injection

CVE-2026-65462 · Severity: high · CVSS 7.6 · Published 2026-07-23

Technologies: Uncanny Owl Uncanny Automator. Vendors: Uncanny Owl.

Executive brief

Uncanny Automator is a popular WordPress plugin used to create automated workflows between different apps and plugins. A security vulnerability in versions 7.3.2 and earlier could allow an administrative user to execute unauthorized database commands. This could lead to the exposure of sensitive site information or unauthorized modification of the database.

Technical details

A SQL injection vulnerability exists in the Uncanny Automator plugin for WordPress (versions <= 7.3.2) due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is accessible via the network but requires high privileges (Administrator level) to exploit. An attacker with sufficient permissions can bypass intended software logic to query or modify the underlying WordPress database. The issue is resolved in version 7.4.0.

Affected products

  • Uncanny Owl Uncanny Automator <= 7.3.2

Timeline

  • 2026-06-30: other: Reported by researcher Ananda Dhakal
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Version 7.4.0 released to address the vulnerability

References

Related threats