CVE · High

CVE-2026-32553 — OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.36

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32553 OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.36 Server-Side Request Forgery (SSRF) High 7.2 < 1.1.36 1.1.36 2026-06-04

CVE-2026-32553

The OttoKit plugin for WordPress allows unauthenticated attackers to make malicious web requests on behalf of the application, potentially enabling them to access and modify sensitive internal data. This vulnerability arises from the plugin's failure to properly validate user requests, allowing attackers to craft requests that originate from the application itself. As a result, attackers can exploit this weakness to query and manipulate internal services without needing authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.