Tech

OttoKit WordPress plugin has a serious security flaw, thousands of users possibly affected

Share
Share


  • The OttoKit plugin was vulnerable to a critical flaw that allows the creation of new admin accounts
  • It was patched in late April 2025, so users should update now
  • Threat actors are looking for exposed websites

OttoKit, a popular automation WordPress plugin, is vulnerable to a critical-severity flaw that allows threat actors to take over entire websites.

The bug is described as an incorrect privilege assignment flaw in Brainstorm Force that allows privilege escalation. It affects all older versions of the website builder plugin, up until version 1.0.83, which was released on April 21, 2025. It is tracked as CVE-2025-27007 and has a severity score of 9.8/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Many IT heads want to ditch US cloud services – but does the UK have an alternative?
Tech

Many IT heads want to ditch US cloud services – but does the UK have an alternative?

Half of UK businesses want to ditch US cloud providers Many have...

Judge orders Trump admin to release billions in EV charging funds
Tech

Judge orders Trump admin to release billions in EV charging funds

California is the US state with the largest number of electric vehicles....

MobLand season 2: everything we know so far about the hit Paramount+ show’s return
Tech

MobLand season 2: everything we know so far about the hit Paramount+ show’s return

MobLand season 2: key information – Officially renewed in June– Main cast...

Gold from e-waste opens a rich vein for miners and the environment
Tech

Gold from e-waste opens a rich vein for miners and the environment

Gold recovered from electronic waste in the Flinders University study. Credit: Flinders...