OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation

Within hours of being made public, a high-severity security bug that affected OttoKit (previously SureTriggers) was being actively exploited.

The vulnerability, identified as CVE-2025-3102 (CVSS score: 8.1), is an authorization bypass flaw that, in some circumstances, could allow an attacker to take over vulnerable websites and create administrator accounts.

A missing empty value check on the’secret_key’ value in the ‘autheticate_user’ function in all versions up to and including 1.0.78 makes the SureTriggers: All-in-One Automation Platform plugin for WordPress susceptible to an authentication bypass that could result in the creation of an administrative account, according to Wordfence’s István Márton.

When the plugin is installed, this enables unauthenticated attackers to establish administrator accounts on the target website read more about OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *