PT-2026-38676 · WordPress · Ottokit: All-In-One Automation Platform

Mcdruid

·

Published

2026-05-08

·

Updated

2026-05-26

·

CVE-2026-4935

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OttoKit: All-in-One Automation Platform WordPress plugin versions prior to 1.1.23
Description Insufficient sanitization of user input used in a SQL statement allows unauthenticated attackers to perform SQL injection attacks.
Recommendations Update the plugin to version 1.1.23 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4935

Affected Products

Ottokit: All-In-One Automation Platform