ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation

highVulnerability exploited in the wildimportance 60CVE-2025-3102

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-3102
Unauthenticated Admin Account Creation in SureTriggers/OttoKit WordPress Plugin

The SureTriggers (OttoKit) All-in-One Automation Platform WordPress plugin fails to check whether the 'secret_key' value is empty in its 'authenticate_user' function, an incorrect-comparison flaw (CWE-697) that enables an authentication bypass in all versions up to and including 1.0.78. An unauthenticated attacker can trigger the flaw simply by sending requests to the affected site when the plugin is installed and activated but has not been configured with an API key. By bypassing authentication, the attacker can create new administrator accounts and achieve full administrative takeover of the WordPress site. Any WordPress site running the vulnerable plugin under those conditions is affected. Headlines report the flaw is under active exploitation in the wild, consistent with its high EPSS score of 75.9% (99th percentile), although no public proof-of-concept is listed.

Do: Update the SureTriggers/OttoKit plugin to a patched release beyond 1.0.78 as soon as possible. As an interim mitigation, configure the plugin with an API key (setting the secret key) or deactivate the plugin until it can be updated. Check the WordPress users list for unfamiliar administrator accounts created recently and review authentication logs for signs of exploitation.

8.176%
  • SureTriggers (OttoKit) SureTriggers: All-in-One Automation Platform (OttoKit) WordPress plugin all versions up to and including 1.0.78
large≈100,000+ WordPress sites (plugin has 100k+ active installs; exploitable subset lacks a configured API key)
Full article427 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 11, 2025Website Security / Vulnerability

A newly disclosed high-severity security flaw impacting OttoKit (formerly SureTriggers) has come under active exploitation within a few hours of public disclosure.

The vulnerability, tracked as CVE-2025-3102 (CVSS score: 8.1), is an authorization bypass bug that could permit an attacker to create administrator accounts under certain conditions and take control of susceptible websites.

"The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78," Wordfence's István Márton said.

"This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key."

Successful exploitation of the vulnerability could permit an attacker to gain complete control over a WordPress site and leverage the unauthorized access to upload arbitrary plugins, make malicious modifications to serve malware or spam, and even redirect site visitors to other sketchy websites.

Security researcher Michael Mazzolini (aka mikemyers) has been credited with discovering and reporting the flaw on March 13, 2025. The issue has been addressed in version 1.0.79 of the plugin released on April 3, 2025.

OttoKit offers the ability for WordPress users to connect different apps and plugins through workflows that can be used to automate repetitive tasks.

While the plugin has over 100,000 active installations, it bears noting that only a subset of the websites are actually exploitable due to the fact that it hinges on the plugin to be in a non-configured state despite being installed and activated.

That said, attackers have already jumped in on the exploitation bandwagon, attempting to quickly capitalize on the disclosure to create bogus administrator accounts with the usernames "xtw1838783bc" or "test123123," per Patchstack..

"Since it is randomized it is highly likely to assume that username, password, and email alias will be different for each exploitation attempt," the WordPress security company said.

The attack attempts have originated from four different IP addresses -

  • 2a01:e5c0:3167::2 (IPv6)
  • 2602:ffc8:2:105:216:3cff:fe96:129f (IPv6)
  • 89.169.15.201 (IPv4)
  • 107.173.63.224 (IPv4)

In light of active exploitation, WordPress site owners relying on the plugin are advised to apply the updates as soon as possible for optimal protection, check for suspicious admin accounts, and remove them.

(The story has been updated after publication with additional indicators of compromise.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/04/ottokit-wordpress-plugin-admin-creation.html