• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-ottokit-wordpress-plugin-flaw-to-add-admin-accounts/

Hackers exploit OttoKit WordPress plugin flaw to add admin accounts

BleepingComputer
·
Bill Toulas
·
Published May 7, 2025
·
Updated

Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on targeted sites. OttoKit (formerly SureTriggers) is a WordPress automation and integration plugin used in over 100,000 sites, allowing users to connect their websites to third-party services and automate workflows. Patchstack received a report about a critical vulnerability in OttoKit on April 11, 2025, from researcher Denver Jackson. The flaw, tracked under the identifier CVE-2025-27007, allows attackers to gain administrator access via the plugin's API by exploiting a logic error in the 'create_wp_connection' function, bypassing authentication checks when application passwords aren't set. The vendor was informed the next day, and a patch was released on April 21, 2025, with OttiKit version 1.0.83, adding a validation check for the access key used in the request. By April 24, 2025, most plugin users had been force-updated to the patched version. Patchstack published its report on May 5, 2025, but a new update warns that exploitation activity started roughly 90 minutes after public disclosure. Attackers attempted exploitation by targeting REST API endpoints, sending requests mimicking legitimate integration attempts, using 'create_wp_connection' with guessed or brute-forced administrator usernames, random passwords, and fake access keys and email addresses. Once the initial exploit was successful, attackers issued follow-up API...

Read full article

Affected Software

4 affected components
OttoKit WordPress plugin=1.0.82
OttoKit WordPress plugin=1.0.81
OttoKit WordPress plugin=1.0.80
OttoKit WordPress plugin

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the OttoKit WordPress plugin that allows hackers to create rogue admin accounts.

2

What is the nature of the vulnerability in the OttoKit plugin?

The vulnerability is an unauthenticated privilege escalation flaw that enables unauthorized access to admin functions.

3

How many sites are using the affected OttoKit plugin?

The OttoKit plugin is used in over 100,000 WordPress sites.

4

What actions are hackers taking by exploiting this vulnerability?

Hackers are exploiting the vulnerability to add unauthorized admin accounts on targeted WordPress sites.

5

What should WordPress users do in response to this security issue?

WordPress users should update their OttoKit plugin to the latest version to mitigate the risk of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203