Tuesday, April 15, 2025
HomeCyber Attack50,000+ WordPress Sites Vulnerable to Privilege Escalation Attacks

50,000+ WordPress Sites Vulnerable to Privilege Escalation Attacks

Published on

SIEM as a Service

Follow Us on Google News

In a recent cybersecurity development, over 50,000 WordPress websites using the Uncanny Automator plugin have been identified as vulnerable to a critical privilege escalation attack.

This vulnerability, discovered by security researcher mikemyers through the Wordfence Bug Bounty Program, allows authenticated attackers with subscriber-level access or higher to escalate their privileges to that of an administrator.

Vulnerability Details and Impact

The vulnerability, present in Uncanny Automator versions up to and including 6.3.0.2, stems from improper capability checks in the plugin’s REST API endpoint.

- Advertisement - Google News

This lack of validation allows attackers to manipulate user roles, potentially granting them full administrative control over affected websites.

With administrative access, attackers could upload malicious files, redirect users, or even inject spam content, leading to significant security breaches.

Wordfence, upon validating the exploit, assigned the vulnerability a high CVSS score of 8.8, highlighting its severity.

The researcher was awarded a bounty of $1,065.00 for uncovering and responsibly disclosing this issue.

Response and Patch

Upon notification from Wordfence, the Uncanny Owl team promptly responded and released an initial patch on March 17, 2025, followed by a fully compliant update to version 6.4.0 on April 1, 2025.

This swift action underscores the importance of timely security updates in software development.

Wordfence has taken measures to protect its users from this vulnerability.

Premium, Care, and Response users received a firewall rule on March 7, 2025, to block potential exploits.

Free version users will receive similar protection on April 6, 2025, after the standard 30-day delay.

We strongly advise all users of Uncanny Automator to upgrade to the latest patched version immediately.

According to the Report, The cybersecurity community’s focus on identifying and patching such vulnerabilities is crucial in maintaining the integrity and security of the WordPress ecosystem, particularly in plugins with significant user bases.

As the WordPress platform continues to evolve, the commitment to “defense in depth” through vulnerabilities’ responsible disclosure and quick patching remains paramount.

This incident serves as a reminder of the ongoing need for vigilance and prompt action in the face of emerging cyber threats.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...