Tech

OttoKit WordPress plugin has a serious security flaw, thousands of users possibly affected

Share
Share


  • The OttoKit plugin was vulnerable to a critical flaw that allows the creation of new admin accounts
  • It was patched in late April 2025, so users should update now
  • Threat actors are looking for exposed websites

OttoKit, a popular automation WordPress plugin, is vulnerable to a critical-severity flaw that allows threat actors to take over entire websites.

The bug is described as an incorrect privilege assignment flaw in Brainstorm Force that allows privilege escalation. It affects all older versions of the website builder plugin, up until version 1.0.83, which was released on April 21, 2025. It is tracked as CVE-2025-27007 and has a severity score of 9.8/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Researchers outline innovative ways to track heat in advanced semiconductors
Tech

Researchers outline innovative ways to track heat in advanced semiconductors

UConn’s School of Mechanical, Aerospace, and Manufacturing Engineering Ph.D. candidate Francis Vásquez...

Researchers achieve record-setting perovskite tandem solar cell with novel NIR-harvesting molecule
Tech

Researchers achieve record-setting perovskite tandem solar cell with novel NIR-harvesting molecule

A team of scientists from the National University of Singapore achieved a...

70% of people are sick of talking to AI – where did all the humans go?
Tech

70% of people are sick of talking to AI – where did all the humans go?

For every one person who prefers interacting with AI, 4.4 prefer speaking...