Tech

WordPress plugin auth bypass exploited almost immediately after disclosure

Share
Share


  • A bug in OttoKit allows threat actors to create new admin accounts
  • The bug can lead to full website takeover
  • More than 100,000 websites are at risk

Almost immediately after being disclosed to the public, a vulnerability in a WordPress plugin was used in an attack, security researchers have warned.

Earlier this week, security outfit Wordfence disclosed an authentication bypass in OttoKit, the all-in-one workflow authentication platform. The vulnerability is tracked as CVE-2025-3102, and was given a severity score 8.1/10 (high).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Samsung Galaxy Z Flip 7 rumored specs: predictions for every key spec
Tech

Samsung Galaxy Z Flip 7 rumored specs: predictions for every key spec

The Samsung Galaxy Z Flip 7 might not be a comprehensive upgrade...

Agatha Christie’s AI ghost is here to teach you how to kill…at writing mystery stories
Tech

Agatha Christie’s AI ghost is here to teach you how to kill…at writing mystery stories

BBC Maestro has launched a writing course taught posthumously by an AI...

Online shopping is now a bot fest — real users just lost the internet to AI-powered fake shoppers
Tech

Online shopping is now a bot fest — real users just lost the internet to AI-powered fake shoppers

Report warns sophisticated bots mimic human behavior so well outdated defenses don’t...

Is the UK’s energy storage growing fast enough?
Tech

Is the UK’s energy storage growing fast enough?

Credit: Pixabay/CC0 Public Domain Britain’s booming green energy generation has a costly...