ZeroHour

CVE-2025-27007

large

Privilege Escalation in Brainstorm Force OttoKit WordPress Plugin (≤ 1.0.82)

CVSS 3.1
9.8 critical
EPSS
51%p99
Published
()
Modified
AI analysis

CVE-2025-27007 is an incorrect privilege assignment flaw (CWE-266) in the OttoKit (SureTriggers) WordPress plugin by Brainstorm Force that allows attackers to escalate privileges. Per the assigned CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N), it is exploitable remotely over the network without credentials or user interaction, making it triggerable directly against vulnerable WordPress sites. A successful attacker gains high-impact privileges — confidentiality, integrity, and availability are all rated high — effectively enabling full site compromise. Any WordPress site running OttoKit version 1.0.82 or earlier is affected, and the plugin is reported to have 100,000+ active installs. There is no public proof-of-concept and the flaw is not in CISA KEV, but EPSS puts the 30-day exploitation probability at 51.5% (99th percentile), and news reports indicate the plugin is being hit by exploits targeting multiple of its flaws.

What to do: Update OttoKit to the latest available release newer than 1.0.82 immediately, as all versions up to and including 1.0.82 are vulnerable. Until patched, check sites for unexpected administrator accounts or modified user roles, and consider temporarily deactivating the plugin if an update is not possible. Note that reports indicate multiple flaws in this plugin are under active exploitation, so patching and a user-account review should be treated as urgent.

Affected
Brainstorm Force OttoKit (SureTriggers) WordPress pluginall versions through 1.0.82 (inclusive)
Estimated exposure
large≈100,000+ WordPress sites (plugin reported at 100K+ active installs) — News reporting cites OttoKit's active install base at 100,000+ WordPress sites, and each vulnerable install corresponds to one exposed site.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news