Tech

OttoKit WordPress plugin has a serious security flaw, thousands of users possibly affected

Share
Share


  • The OttoKit plugin was vulnerable to a critical flaw that allows the creation of new admin accounts
  • It was patched in late April 2025, so users should update now
  • Threat actors are looking for exposed websites

OttoKit, a popular automation WordPress plugin, is vulnerable to a critical-severity flaw that allows threat actors to take over entire websites.

The bug is described as an incorrect privilege assignment flaw in Brainstorm Force that allows privilege escalation. It affects all older versions of the website builder plugin, up until version 1.0.83, which was released on April 21, 2025. It is tracked as CVE-2025-27007 and has a severity score of 9.8/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Study reveals how writers compete with AI
Tech

Study reveals how writers compete with AI

Credit: CC0 Public Domain Writers are not passive victims of AI disruption...

Top medical device maker Masimo confirms cyberattack, says products may be delayed
Tech

Top medical device maker Masimo confirms cyberattack, says products may be delayed

Masimo Corporation files new report with the SEC confirming attack It says...

Ping pong robot returns shots with high-speed precision
Tech

Ping pong robot returns shots with high-speed precision

Time lapse photos show a new ping-pong-playing robot performing a top spin....

Apple exec suggests you ‘may not need’ an iPhone in 10 years’ time
Tech

Apple exec suggests you ‘may not need’ an iPhone in 10 years’ time

Apple’s head of services Eddy Cue has suggested that users may not...