TechBriefly
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
No Result
View All Result
TechBriefly
Home Tech Security
WordPress OttoKit plugin hacked after authentication bypass disclosure

WordPress OttoKit plugin hacked after authentication bypass disclosure

TB EditorbyTB Editor
11 April 2025
in Security
Reading Time: 1 min read
Share on FacebookShare on Twitter

Hackers began exploiting a high-severity authentication bypass vulnerability in the OttoKit WordPress plugin just hours after its public disclosure, posing a significant risk to users.

The OttoKit WordPress plugin, formerly known as SureTriggers, allows users to connect various plugins and external tools like WooCommerce, Mailchimp, and Google Sheets to automate tasks without code. With the plugin active on 100,000 websites, the vulnerability identified as CVE-2025-3102 impacts all versions up to 1.0.78.

The flaw stems from a missing empty value check in the authenticate_user() function, which handles REST API authentication. If the plugin is not configured with an API key, the stored secret_key remains empty, allowing exploitation. An attacker can exploit this vulnerability by sending an empty st_authorization header, thereby bypassing authentication and gaining unauthorized access to protected API endpoints.

Essentially, CVE-2025-3102 enables attackers to create new administrator accounts without authentication, potentially leading to full site takeover. The vulnerability was reported to Wordfence by security researcher ‘mikemyers’ in mid-March, who received a $1,024 bounty for the discovery.

The plugin vendor was notified on April 3rd and released a fix in version 1.0.79 on the same day. However, exploitation attempts began just hours after the public disclosure of the vulnerability. Researchers at Patchstack reported that the first exploitation attempt was logged just four hours after the vulnerability was added to their database.

Attackers are attempting to create new administrator accounts with randomized username, password, and email address combinations, indicating automated attacks. Users of the OttoKit/SureTriggers plugin are strongly advised to upgrade to version 1.0.79 immediately and check logs for suspicious activity, such as new admin accounts, installation of plugins or themes, database access events, and modification of security settings.

Tags: hackpluginWordPress
ShareTweet
TB Editor

TB Editor

Related Posts

Anna’s Archive leaks 300TB of Spotify’s music catalog

Anna’s Archive leaks 300TB of Spotify’s music catalog

22 December 2025
EU regulators accuse TikTok of ongoing data transfers to China

EU regulators accuse TikTok of ongoing data transfers to China

22 December 2025
Cisco announces hackers exploiting AsyncOS zero-day

Cisco announces hackers exploiting AsyncOS zero-day

19 December 2025
Koi uncovers data harvesting in Urban VPN Proxy

Koi uncovers data harvesting in Urban VPN Proxy

19 December 2025

LATEST

New WhatsApp update brings 2026 stickers and video call effects

Leaker reveals Xiaomi plans for high end eSIM device in 2026

HP prepares OMEN OLED monitor reveal for CES 2026

High RAM costs from AI boom could delay next Xbox and PlayStation

LG to unveil its Gallery TV at CES 2026

Bitcoin drops 3% to $87,300 as altcoins decline

How to install mods and custom content in The Sims 2

Running Python files and fixing path errors on Windows

How to boot your PC into Command Prompt for troubleshooting

How to delete a virus using Command Prompt

TechBriefly

© 2021 TechBriefly is a Linkmedya brand.

  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
  • Privacy
  • Terms
  • Contact
  • | Network Sites |
  • Digital Report
  • LeaderGamer

Follow Us

No Result
View All Result
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska