CVE-2025-27007 Details
Description
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
A privilege escalation vulnerability has been identified in the Brainstorm Force OttoKit (formerly SureTriggers) WordPress plugin, affecting versions through 1.0.82. This vulnerability allows unauthenticated users to gain elevated privileges by exploiting a logic error in the plugin's handling of application password authentication. As a result, an attacker could potentially take full control of a WordPress site via the OttoKit API, including the ability to create new administrator accounts, particularly on sites where the admin has not set an application password.
Users of the OttoKit WordPress plugin should update to version 1.0.83 or later. Patchstack users are already protected from this vulnerability and no further action is required.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2025CISA-ADP
Assessed May 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://patchstack.com/database/Wordpress/Plugin/suretriggers/vulnerability/wordpress-suretriggers-1-0-82-privilege-escalation-vulnerability?_s_id=cve | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Brainstorm Force SureTriggers | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| May 5, 2025 | CVE Modified | [email protected] |
| May 1, 2025 | New CVE Received | [email protected] |
Volerion