Tech

OttoKit WordPress plugin has a serious security flaw, thousands of users possibly affected

Share
Share


  • The OttoKit plugin was vulnerable to a critical flaw that allows the creation of new admin accounts
  • It was patched in late April 2025, so users should update now
  • Threat actors are looking for exposed websites

OttoKit, a popular automation WordPress plugin, is vulnerable to a critical-severity flaw that allows threat actors to take over entire websites.

The bug is described as an incorrect privilege assignment flaw in Brainstorm Force that allows privilege escalation. It affects all older versions of the website builder plugin, up until version 1.0.83, which was released on April 21, 2025. It is tracked as CVE-2025-27007 and has a severity score of 9.8/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
World Video Game Hall of Fame inducts Defender, Tamagotchi, GoldenEye 007 and Quake
Tech

World Video Game Hall of Fame inducts Defender, Tamagotchi, GoldenEye 007 and Quake

This photo, provided by The Strong Museum in Rochester, N.Y., shows “Defender”,...

Decentralized finance is booming, and so are the security risks
Tech

Decentralized finance is booming, and so are the security risks

Credit: CC0 Public Domain When the first cryptocurrency, Bitcoin, was proposed in...

How to tell if a photo’s fake? You probably can’t. That’s why new rules are needed
Tech

How to tell if a photo’s fake? You probably can’t. That’s why new rules are needed

Credit: Unsplash/CC0 Public Domain The problem is simple: it’s hard to know...