CVE-2025-27007
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allows Privilege Escalation.This issue affects SureTriggers: from n/a through 1.0.82.
The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.82. This is due to the create_wp_connection() function missing a capability check and insufficiently verifying a user's authentication credentials. This makes it possible for unauthenticated attackers to establish a connection, which ultimately can make privilege escalation possible.
WordPress OttoKit plugin versions 1.0.82 and below suffer from a privilege escalation vulnerability. This plugin used to be called SureTriggers.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-02-17 CVE Reserved
- 2025-04-30 CVE Published
- 2025-05-05 CVE Updated
- 2025-05-07 First Exploit
- 2025-06-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-266: Incorrect Privilege Assignment
- CWE-862: Missing Authorization
CAPEC
- CAPEC-233: Privilege Escalation
References (8)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/190854 | 2025-05-07 | |
https://www.exploit-db.com/exploits/52286 | 2025-05-09 | |
https://github.com/absholi7ly/CVE-2025-27007-OttoKit-exploit | 2025-05-12 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Suretriggers Search vendor "Suretriggers" | Suretriggers Search vendor "Suretriggers" for product "Suretriggers" | >= 0.0.0 <= 1.0.82 Search vendor "Suretriggers" for product "Suretriggers" and version " >= 0.0.0 <= 1.0.82" | en |
Affected
|