The Ottokit WordPress complement has a serious security defect, thousands of possibly affected users




  • The Ottokit complement was vulnerable to a critical failure that allows the creation of new administration accounts
  • It was a pairing at the end of April 2025, so users should now update
  • Threat actors are looking for exposed websites

Ottokit, a popular automation wordpress complement, is vulnerable to a critical severity defect that allows threat actors to take care of complete websites.

The error is described as an incorrect privilege allocation failure in the force of the rain of ideas that allows the escalation of privileges. It affects all the previous versions of the Builder Builder complement, to version 1.0.83, which was launched on April 21, 2025. They are tracked as CVE-2025-27007 and has a gravity score of 9.8/10 (critical).

Leave a Comment

Your email address will not be published. Required fields are marked *