WP Clinic
Log in Sign up

CVE · Critical

CVE-2025-27007 — OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-27007 OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83 Incorrect Privilege Assignment Critical 9.8 < 1.0.83 1.0.83 2025-04-30

CVE-2025-27007

The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.82. This is due to the create_wp_connection() function missing a capability check and insufficiently verifying a user's authentication credentials. This makes it possible for unauthenticated attackers to establish a connection, which ultimately can make privilege escalation possible.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.