🚨 URGENT: Hackers Actively Exploiting OttoKit WordPress Plugin Flaw (May 2025) 🚨
🔍 What's Happening?
Cybercriminals are exploiting a critical vulnerability (CVE-2025-27007) in the OttoKit WordPress plugin to:
- Create unauthorized admin accounts
- Gain full control of vulnerable websites
- Potentially deploy malware or steal data
📊 Key Details:
• Impact: 100,000+ WordPress sites using OttoKit (formerly SureTriggers)
• Vulnerability: Authentication bypass in 'create_wp_connection' function
• Patch Released: April 21 in version 1.0.83
• Active Exploitation: Began 90 minutes after public disclosure
💥 Attack Pattern:
1. Hackers target REST API endpoints
2. Send requests mimicking legitimate integrations
3. Exploit creates hidden admin accounts with:
- Random usernames/passwords
- Fake email addresses
- "create_user_if_not_exists" payloads
🛡️ Protection Steps:
1. Immediately update to OttoKit v1.0.83+
2. Audit user accounts for suspicious admins
3. Check logs for API calls to:
- /wp-json/sure-triggers/v1/automation/action
- ?rest_route=/wp-json/sure-triggers/v1/automation/action
⚠️ Critical Note:
This is the SECOND major OttoKit exploit in April-May 2025, following CVE-2025-3102. Automated attacks are targeting both vulnerabilities.
📢 Spread Awareness!
WordPress admins need to act NOW. Share this alert! #WordPressSecurity #CyberAlert
[Source: BleepingComputer, Patchstack]
💬 Need Help?
Drop questions below for security recommendations.
Post #1597
496