CVE Database /
CVE-2026-49781
CVE · Critical
CVE-2026-49781 — OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.28
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-49781
|
OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.28 |
Deserialization of Untrusted Data |
Critical
9.8
|
< 1.1.28
|
1.1.28 |
2026-05-11 |
—
|
CVE-2026-49781
The OttoKit: All-in-One Automation Platform WordPress plugin contains a vulnerability that allows malicious input to be deserialized as PHP objects in versions prior to 1.1.28, potentially enabling unauthenticated attackers to inject and manipulate system objects. This could lead to unauthorized actions such as deleting files or accessing sensitive data if other plugins or themes on the site are compromised by an additional attack vector.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings