WordPress Plugin Author bypassing almost immediately after disclosure


  • A bug in Ottokit allows threat actors to create new administration accounts
  • The bug can lead to the complete takeover of the website
  • More than 100,000 websites are at risk

Almost immediately after being disclosed to the public, a vulnerability in a WordPress plugin was used in an attack, warned researchers warned.

Earlier this week, WordFence security clothing revealed an authentication bypass in Ottokit, the all-in-one workflow platform. Vulnerability is followed as CVE-2025-3102 and received a gravity score of 8.1 / 10 (high).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top