- The Ottokit -Plugin was vulnerable to a critical mistake that allows the creation of new admin accounts
- It was patched at the end of April 2025 so users had to update now
- Threat players are looking for exposed sites
Ottokit, a popular Automation WordPress plugin, is vulnerable to an error in critical difficulty that allows threat players to take over entire sites.
The error is described as an incorrect privilege allocation error in brainstorm power that allows privilege shell. It affects all older versions of Website Builder Plugin until version 1.0.83, which was released on April 21, 2025. It is traced as CVE-2025-27007 and has a severity of 9.8/10 (critical).
In theory, threat actors could send a designed postal -maturity to a vulnerable residual API point exposed by Ottokit containing automation data that mimics internal plugin logic. Due to lack of validation, Ottokit would fail to approve the request correctly, and as the automation logic runs with increased privileges, the threat actors are ultimately allowed to create a new user account and assign the administrator role.
Chats leaked
Ottokit, formerly known as Suretriggers, is designed to connect sites with various third -party services and enable workflow automation without coding.
It supports integrations with platforms such as WOOCOMMERCE, MailChimp, Google Sheets and CRMS so that users can run tasks such as sending E emails, updating user roles or synchronizing data across apps.
Plugin has more than 100,000 users, but most of them have already used the patch. Still, security researchers said Patchstack that they observed attacks in nature, and started almost immediately after the error was published.
“It is highly recommended to update your site as soon as possible if you use Ottokit plugin and to review your logs and site settings for these attacks and compromise indicators,” Patchstack said.
This is the second major vulnerability in Ottokit found this month, after CVE-2010-3102, another approval city pass error that received a “high” severity of 8.1/10.
Via Bleeping computer