CVE-2026-32553: WordPress OttoKit plugin <= 1.1.35 - Server Side Request Forgery (SSRF) vulnerability
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress OttoKit Pluginto a version that resolves this vulnerability.Fixed in 1.1.36
Event History
Frequently Asked Questions
Which installations are affected?
Sites running OttoKit version 1.1.35 or earlier are identified as affected. The available data does not state whether any particular OttoKit configuration or feature must be enabled.
What access does an attacker need to exploit this?
Exploitation is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The network attack vector and low attack complexity indicate it can be attempted remotely with little complexity.
What can defenders do if a patch is not immediately available?
The provided information does not identify temporary mitigations, affected endpoints, indicators of compromise, or a fixed version. Until update guidance is available, identify installations of OttoKit at version 1.1.35 or earlier and monitor vendor advisories.