PT-2025-15910 · WordPress · Suretriggers
Michael Mazzolini
·
Published
2025-04-09
·
Updated
2025-09-29
·
CVE-2025-3102
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OttoKit (formerly SureTriggers) versions 1.0.0 through 1.0.78
Description
The vulnerability is related to an authentication bypass issue in the OttoKit WordPress plugin, which allows unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key. This is due to a missing empty value check on the
secret key value in the autheticate user function. The issue has been actively exploited, with over 100,000 WordPress sites potentially at risk. Attackers can create admin accounts and fully take over vulnerable sites.Recommendations
For versions 1.0.0 through 1.0.78, update to version 1.0.79 immediately to prevent unauthorized access.
As a temporary workaround, consider disabling the
autheticate user function until a patch is available.
Restrict access to the REST API endpoints to minimize the risk of exploitation.
Check admin users and remove any suspicious accounts.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suretriggers