CVE-2025-27007
largePrivilege Escalation in Brainstorm Force OttoKit WordPress Plugin (≤ 1.0.82)
CVE-2025-27007 is an incorrect privilege assignment flaw (CWE-266) in the OttoKit (SureTriggers) WordPress plugin by Brainstorm Force that allows attackers to escalate privileges. Per the assigned CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N), it is exploitable remotely over the network without credentials or user interaction, making it triggerable directly against vulnerable WordPress sites. A successful attacker gains high-impact privileges — confidentiality, integrity, and availability are all rated high — effectively enabling full site compromise. Any WordPress site running OttoKit version 1.0.82 or earlier is affected, and the plugin is reported to have 100,000+ active installs. There is no public proof-of-concept and the flaw is not in CISA KEV, but EPSS puts the 30-day exploitation probability at 51.5% (99th percentile), and news reports indicate the plugin is being hit by exploits targeting multiple of its flaws.
What to do: Update OttoKit to the latest available release newer than 1.0.82 immediately, as all versions up to and including 1.0.82 are vulnerable. Until patched, check sites for unexpected administrator accounts or modified user roles, and consider temporarily deactivating the plugin if an update is not possible. Note that reports indicate multiple flaws in this plugin are under active exploitation, so patching and a user-account review should be treated as urgent.
| Brainstorm Force OttoKit (SureTriggers) WordPress plugin | all versions through 1.0.82 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H