WordPress plugin auth bypass exploited almost immediately after disclosure

WordPress plugin auth bypass exploited almost immediately after disclosure

  • A bug in OttoKit allows threat actors to create new admin accounts
  • The bug can lead to full website takeover
  • More than 100,000 websites are at risk

Almost immediately after being disclosed to the public, a vulnerability in a WordPress plugin was used in an attack, security researchers have warned.

Earlier this week, security outfit Wordfence disclosed an authentication bypass in OttoKit, the all-in-one workflow authentication platform. The vulnerability is tracked as CVE-2025-3102, and was given a severity score 8.1/10 (high).



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *


Enable Notifications OK No thanks