Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on targeted sites. OttoKit (formerly SureTriggers) is a WordPress automation and integration plugin used in over 100,000 sites, allowing users to connect their websites to third-party services and automate workflows. Patchstack received a report about a critical vulnerability in OttoKit on April 11, 2025, from researcher Denver Jackson. The flaw, tracked under the identifier CVE-2025-27007, allows attackers to gain administrator access via the plugin's API by exploiting a logic error in the 'create_wp_connection' function, bypassing authentication checks when application passwords aren't set. The vendor was informed the next day, and a patch was released on April 21, 2025, with OttiKit version 1.0.83, adding a validation check for the access key used in the request. By April 24, 2025, most plugin users had been force-updated to the patched version. Patchstack published its report on May 5, 2025, but a new update warns that exploitation activity started roughly 90 minutes after public disclosure. Attackers attempted exploitation by targeting REST API endpoints, sending requests mimicking legitimate integration attempts, using 'create_wp_connection' with guessed or brute-forced administrator usernames, random passwords, and fake access keys and email addresses. Once the initial exploit was successful, attackers issued follow-up API...
Hackers exploit OttoKit WordPress plugin flaw to add admin accounts
BleepingComputer
·Bill Toulas
·Published May 7, 2025
·Updated
Affected Software
4 affected components
OttoKit WordPress plugin=1.0.82
OttoKit WordPress plugin=1.0.81
OttoKit WordPress plugin=1.0.80
OttoKit WordPress plugin
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in the OttoKit WordPress plugin that allows hackers to create rogue admin accounts.
2
What is the nature of the vulnerability in the OttoKit plugin?
The vulnerability is an unauthenticated privilege escalation flaw that enables unauthorized access to admin functions.
3
How many sites are using the affected OttoKit plugin?
The OttoKit plugin is used in over 100,000 WordPress sites.
4
What actions are hackers taking by exploiting this vulnerability?
Hackers are exploiting the vulnerability to add unauthorized admin accounts on targeted WordPress sites.
5
What should WordPress users do in response to this security issue?
WordPress users should update their OttoKit plugin to the latest version to mitigate the risk of exploitation.