CVE Database /
CVE-2025-27007
CVE · Critical
CVE-2025-27007 — OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-27007
|
OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83 |
Incorrect Privilege Assignment |
Critical
9.8
|
< 1.0.83
|
1.0.83 |
2025-04-30 |
—
|
CVE-2025-27007
The OttoKit plugin for WordPress has an issue with its create_wp_connection function in versions up to 1.0.82. The function fails to properly verify the capabilities of users and their authentication credentials, allowing unauthorized individuals to initiate connections that could potentially lead to elevated privileges. This vulnerability affects all versions of the plugin prior to 1.0.82.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings