CVE · Critical

CVE-2025-27007 — OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-27007 OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83 Incorrect Privilege Assignment Critical 9.8 < 1.0.83 1.0.83 2025-04-30

CVE-2025-27007

The OttoKit plugin for WordPress has an issue with its create_wp_connection function in versions up to 1.0.82. The function fails to properly verify the capabilities of users and their authentication credentials, allowing unauthorized individuals to initiate connections that could potentially lead to elevated privileges. This vulnerability affects all versions of the plugin prior to 1.0.82.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.