Cybercriminals are exploiting a serious privilege escalation in the WordPress plugin OttoKitto create fake administrator accounts on targeted websites.

OttoKit (formerly SureTriggers) is an automation and integration tool for WordPress, used on over 100,000 websites . The plugin allows administrators to connect their platform with external services and automate workflows.
On April 11 , the Patchstack security team was notified of a critical vulnerability in OttoKit, following a report by researcher Denver Jackson .
See also: Scallywag: New ad-fraud campaign uses WordPress plugins
This particular bug (CVE-2025-27007) allows attackers to gain administrator access via the plugin's API, exploiting a logic error in the "create_wp_connection" function and bypassing authentication checks when application passwords are not set.
The WordPress plugin vendor was immediately notified, and on April 21, 2025, OttoKit version 1.0.83 was released , which incorporated a validation check for access keys . By April 24 , most users had already been forced to download the new, more secure version.
However, exploitation of the vulnerability began just minutes after Patchstack's report was published on May 5 .
Attackers exploited the vulnerability by targeting REST API endpoints, sending requests that looked like valid connection attempts service, using 'create_wp_connection' with brute-forced administrator usernames, random passwords, and fake access keys and email addresses.
See also: WordPress Plugin Vulnerability with 100,000+ Installs is Actively Exploited
If the initial attempt was successful, additional API requests were made to the addresses /wp-json/sure-triggers/v1/automation/action and ?rest_route=/wp-json/sure-triggers/v1/automation/action, including the payload value: “type_event”: “create_user_if_not_exists. On vulnerable websites, this process led to the silent creation of new administrator accounts, without the owner being aware of it.
The Patchstack security team recommends that administrators using OttoKit immediately update the plugin and carefully review logs and settings for signs of a possible breach.
This is the second serious security vulnerability in OttoKit that hackers are exploiting within a short period of time. The previous issue (CVE-2025-3102) also concerned bypassing the authentication mechanism.

WordPress Security
WordPress website security requires a multi-pronged approach to protect against potential threats. One key strategy includes regularly updating plugins and themes to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect your data in the event of an attack.
See also: WordPress: Hackers abuse mu-plugins for attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware , and brute force attack prevention.
Source: www.bleepingcomputer.com
