PT-2025-15910 · WordPress · Suretriggers

Michael Mazzolini

·

Published

2025-04-09

·

Updated

2025-09-29

·

CVE-2025-3102

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OttoKit (formerly SureTriggers) versions 1.0.0 through 1.0.78
Description The vulnerability is related to an authentication bypass issue in the OttoKit WordPress plugin, which allows unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key. This is due to a missing empty value check on the secret key value in the autheticate user function. The issue has been actively exploited, with over 100,000 WordPress sites potentially at risk. Attackers can create admin accounts and fully take over vulnerable sites.
Recommendations For versions 1.0.0 through 1.0.78, update to version 1.0.79 immediately to prevent unauthorized access. As a temporary workaround, consider disabling the autheticate user function until a patch is available. Restrict access to the REST API endpoints to minimize the risk of exploitation. Check admin users and remove any suspicious accounts.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-04970
CVE-2025-3102

Affected Products

Suretriggers