- An error in Ottokit allows threat players to create new admin accounts
- The error can lead to full takeover of sites
- More than 100,000 sites are at risk
Almost immediately after being passed on to the public, a vulnerability in a WordPress plugin used in an attack was warned.
Wordfence revealed an approval compass in Ottokit, the all-in-a-working processing approval platform, the track as CVE-2025-3102, and got a severity of 8.1/10 (high).
It affects all versions of plugin up to 1.0.78 and allows threat actors to create new administrator accounts without approval. The accounts can then be used for full takeover of sites and pose a huge risk of hundreds of thousands of WordPress-driven sites using this plugin. The WordPress Web site showed “100,000+ active installations.”
Hours to attack
The first clean version is 1.0.79, although version 1.0.80 is currently available for download. Users are advised to upgrade their plugin to the latest version as soon as possible, especially as the abuse of wild ones was already observed.
According to Patchstack, the first attempts to exploit the error were logged just “hours” after the error was revealed, Bleeping computer reported.
“Attackers were quick to exploit this vulnerability, with the first recorded trial, only four hours after it was added as a Vpatch to our database,” Patchstack reports.
“This rapid exploitation highlights the critical need to use labels or mitigation immediately after the publication of such vulnerabilities,” the researchers said.
To make it worse, there is evidence that points to the attacks that are automated, which means that thousands of sites can be quickly compromised.
Ottokit is an all-in-one-workflow automation platform designed to connect applications, services and WordPress plugins. It allows users to automate repeated tasks and streamline business processes. It was previously known as surge riggers and supports integration with more than 1,000 apps.
WordPress’ plugins and themes are almost constantly scanned for vulnerabilities. Website owners are advised to uninstall and disable all those they do not use at a given time and keep those they do up to date.
Via Bleeping computer