The WordPress Ottokit plugin has a serious security defect, thousands of users possibly affected


  • The Ottokit plugin was vulnerable to a critical defect which allows the creation of new administration accounts
  • It was corrected at the end of April 2025, so users should update now
  • Threat actors are looking for exposed websites

Ottokit, a WordPress Popular Automation plugin, is vulnerable to a lack of critical severity that allows threat stakeholders to take care of whole websites.

The bug is described as a lack of allocation of incorrect privilege in the strength of the brainstorming which allows a climbing of privilege. It affects all the old versions of the website builder plugin, up to version 1.0.83, which was published on April 21, 2025. It is followed as CVE-2025-27007 and has a 9.8 / 10 (critic) gravity score.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top