CVE Database /
CVE-2025-27007
CVE · Critical
CVE-2025-27007 — OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-27007
|
OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83 |
Incorrect Privilege Assignment |
Critical
9.8
|
< 1.0.83
|
1.0.83 |
2025-04-30 |
—
|
CVE-2025-27007
The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.82. This is due to the create_wp_connection() function missing a capability check and insufficiently verifying a user's authentication credentials. This makes it possible for unauthenticated attackers to establish a connection, which ultimately can make privilege escalation possible.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings