Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    What’s The Average Lifespan Of A Jet Engine?

    As an NBN expert, I can’t believe how affordable Kogan Internet’s NBN 500 plan is — and it’s just scored another price drop

    Xiaomi’s Watch 5 has just launched globally, and it could be an affordable Google Pixel Watch 4 rival

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      What the polls say about how Americans are using AI

      February 27, 2026

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026
    • Business

      These ultra-budget laptops “include” 1.2TB storage, but most of it is OneDrive trial space

      March 1, 2026

      FCC approves the merger of cable giants Cox and Charter

      February 28, 2026

      Finding value with AI and Industry 5.0 transformation

      February 28, 2026

      How Smarsh built an AI front door for regulated industries — and drove 59% self-service adoption

      February 24, 2026

      Where MENA CIOs draw the line on AI sovereignty

      February 24, 2026
    • Crypto

      Bitcoin Bear Market Could Get Worse Despite the Latest Relief Rally

      March 1, 2026

      Crypto Scammers Have Been Quiet in February, Hacks Fall by 90%

      March 1, 2026

      Vitalik Buterin Signals Major Ethereum Wallet Overhaul

      March 1, 2026

      Why is Hyperliquid Price Rallying Amid the US-Iran War

      March 1, 2026

      Arbitrum Price Under Pressure: 60 Million ARB Whale Sale Sparks ATL Fear

      March 1, 2026
    • Technology

      What’s The Average Lifespan Of A Jet Engine?

      March 3, 2026

      As an NBN expert, I can’t believe how affordable Kogan Internet’s NBN 500 plan is — and it’s just scored another price drop

      March 3, 2026

      Xiaomi’s Watch 5 has just launched globally, and it could be an affordable Google Pixel Watch 4 rival

      March 3, 2026

      Amazon Sells Surprisingly Cheap Socket Sets, But Are They Any Good?

      March 3, 2026

      What is the release date for The Pitt season 2 episode 9 on HBO Max?

      March 3, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Hackers exploit WordPress plugin auth bypass hours after disclosure
    Technology

    Hackers exploit WordPress plugin auth bypass hours after disclosure

    TechAiVerseBy TechAiVerseApril 11, 2025No Comments3 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Hackers exploit WordPress plugin auth bypass hours after disclosure
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Hackers exploit WordPress plugin auth bypass hours after disclosure

    Hackers started exploiting a high-severity flaw that allows bypassing authentication in the OttoKit (formerly SureTriggers) plugin for WordPress just hours after public disclosure.

    Users are strongly recommended to upgrade to the latest version of OttoKit/SureTriggers, currently 1.0.79, released at the beginning of the month.

    The OttoKit WordPress plugin allows users to connect plugins and external tools like WooCommerce, Mailchimp, and Google Sheets, automate tasks like sending emails and adding users, or updating CRMs without code. Statistics show that the product is active on 100,000 websites.

    Yesterday, Wordfence disclosed an authentication bypass vulnerability in OttoKit, identified as CVE-2025-3102. The flaw impacts all versions of SureTriggers/OttoKit up to 1.0.78.

    The flaw stems from a missing empty value check in the authenticate_user() function, which handles REST API authentication. Exploitation to be possible if the plugin is not configured with an API key, which causes the stored secret_key to remain empty.

    The vulnerable code
    Source: Wordfence

    An attacker could exploit this by sending an empty st_authorization header to pass the check and grant unauthorized access to protected API endpoints.

    Essentially, CVE-2025-3102 allows attackers to create new administrator accounts without authentication, posing a high risk of full site takeover.

    Wordfence received a report about the flaw from security researcher ‘mikemyers’, who earned a bounty of $1,024 for the discovery in mid-March.

    The plugin vendor was contacted on April 3 with the full exploitation details, and they released a fix via version 1.0.79 on the same day.

    However, hackers quickly jumped at the opportunity to exploit the issue, taking advantage of administrators’ delay in updating the plugin to address the security problem.

    Researchers at WordPress security platform Patchstack are warning that the first exploitation attempts in the wild were logged only a few hours after the disclosure of the flaw.

    “Attackers were quick to exploit this vulnerability, with the first recorded attempt occurring just four hours after it was added as a vPatch to our database,” reports Patchstack.

    “This swift exploitation highlights the critical need to apply patches or mitigations immediately upon the public disclosure of such vulnerabilities,” the researchers say.

    The threat actors attempt to create new administrator accounts using randomized username/password and email address combination, a sign of task automation.

    If you’re using OttoKit/SureTriggers, upgrade to version 1.0.79 as soon as possible and check logs for unexpected admin accounts or other user roles, installation of plugins/themes, database access events, and modification of security settings.


    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleMicrosoft releases emergency update to fix Office 2016 crashes
    Next Article Yahoo removes DEI pages from its website
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    What’s The Average Lifespan Of A Jet Engine?

    March 3, 2026

    As an NBN expert, I can’t believe how affordable Kogan Internet’s NBN 500 plan is — and it’s just scored another price drop

    March 3, 2026

    Xiaomi’s Watch 5 has just launched globally, and it could be an affordable Google Pixel Watch 4 rival

    March 3, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025702 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025285 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025164 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025124 Views
    Don't Miss
    Technology March 3, 2026

    What’s The Average Lifespan Of A Jet Engine?

    What’s The Average Lifespan Of A Jet Engine? Dushlik/Getty Images The dawn of the jet…

    As an NBN expert, I can’t believe how affordable Kogan Internet’s NBN 500 plan is — and it’s just scored another price drop

    Xiaomi’s Watch 5 has just launched globally, and it could be an affordable Google Pixel Watch 4 rival

    Amazon Sells Surprisingly Cheap Socket Sets, But Are They Any Good?

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    What’s The Average Lifespan Of A Jet Engine?

    March 3, 20262 Views

    As an NBN expert, I can’t believe how affordable Kogan Internet’s NBN 500 plan is — and it’s just scored another price drop

    March 3, 20262 Views

    Xiaomi’s Watch 5 has just launched globally, and it could be an affordable Google Pixel Watch 4 rival

    March 3, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    Best TV Antenna of 2025

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.