ZeroHour
Security Affairspublished ()ingested @securityaffairs

Attackers are exploiting recently disclosed OttoKit WordPress plugin flaw

criticalVulnerability exploited in the wildimportance 60CVE-2025-3102

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-3102
Unauthenticated Admin Account Creation in SureTriggers/OttoKit WordPress Plugin

The SureTriggers (OttoKit) All-in-One Automation Platform WordPress plugin fails to check whether the 'secret_key' value is empty in its 'authenticate_user' function, an incorrect-comparison flaw (CWE-697) that enables an authentication bypass in all versions up to and including 1.0.78. An unauthenticated attacker can trigger the flaw simply by sending requests to the affected site when the plugin is installed and activated but has not been configured with an API key. By bypassing authentication, the attacker can create new administrator accounts and achieve full administrative takeover of the WordPress site. Any WordPress site running the vulnerable plugin under those conditions is affected. Headlines report the flaw is under active exploitation in the wild, consistent with its high EPSS score of 75.9% (99th percentile), although no public proof-of-concept is listed.

Do: Update the SureTriggers/OttoKit plugin to a patched release beyond 1.0.78 as soon as possible. As an interim mitigation, configure the plugin with an API key (setting the secret key) or deactivate the plugin until it can be updated. Check the WordPress users list for unfamiliar administrator accounts created recently and review authentication logs for signs of exploitation.

8.176%
  • SureTriggers (OttoKit) SureTriggers: All-in-One Automation Platform (OttoKit) WordPress plugin all versions up to and including 1.0.78
large≈100,000+ WordPress sites (plugin has 100k+ active installs; exploitable subset lacks a configured API key)
Full article509 words · extracted from securityaffairs.com · click to collapse

Threat actors are exploiting a vulnerability in the OttoKit WordPress plugin, a few hours after public disclosure.

Threat actors are exploiting a recently discovered vulnerability, tracked as CVE-2025-3102 (CVSS score of 8.1) in the OttoKit WordPress plugin (formerly SureTriggers), a few hours after public disclosure.

An attacker can trigger the vulnerability to create malicious administrator users when the plugin is not configured with an API key. Exploiting the flaw lets attackers fully take over a WordPress site, upload malicious plugins, alter content, serve malware or spam, and redirect visitors to malicious websites.

“The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the ‘secret_key’ value in the ‘autheticate_user’ function in all versions up to, and including, 1.0.78.” reads the advisory. “This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.”

Wordfence researchers state that over 100,000 sites use the vulnerable plugin, but only a subset is exploitable, as the flaw requires the plugin to be unconfigured. The WordPress cybersecurity firm warns that the flaw is actively exploited, so immediate updates are strongly advised.

“The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the ‘secret_key’ value in the ‘autheticate_user’ function in all versions up to, and including, 1.0.78.” states Wordfence. “This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.”

The WordPress plugin lets users automate actions across sites and apps, but an incomplete permission check in its code can allow attackers to exploit unconfigured sites. If the plugin’s secret key is unset and an attacker sends an empty key, they can bypass authentication and create an admin account. This enables full site takeover. While the flaw mainly affects new or unconfigured setups, it could be chained with other vulnerabilities for wider exploitation.

The researcher Michael Mazzolini discovered the vulnerability on March 13, 2025. The flaw has been addressed with the release of version 1.0.79 on April 3, 2025.

PatchStack researchers confirmed that the flaw is under active exploitation.

Attackers are attempting to exploit the flaw to create administrator accounts with the name “xtw1838783bc”.

“In the exploitation attempts we have seen attackers tried creating user accounts with the following details:”

“Since it is randomized, it is highly likely to assume that username, password and email alias will be different for each exploitation attempt. It is recommended to update your site as soon as possible if you are running the SureTriggers plugin to the latest version and look for all the IOCs in your system like created accounts, recently installed plugins/themes or overall modified content.” states PatchStack.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, OttoKit WordPRess Plugin)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/176461/security/ottokit-wordpress-plugin-flaw-exploitation.html