cognitive cybersecurity intelligence

News and Analysis

Search

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation

A high-severity security flaw, CVE-2025-3102, impacting OttoKit (formerly SureTriggers) that could allow an attacker to create administrator accounts and gain control of vulnerable websites, has been discovered and is under exploitation. Users are advised to apply updates immediately to protect their WordPress sites. Attackers are creating bogus admin accounts, which have originated from two different IP addresses. The flaw has since been addressed in later versions of the plugin.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts