More

    WordPress plugin auth bypass exploited almost immediately after disclosure




    • A bug in OttoKit allows threat actors to create new admin accounts
    • The bug can lead to full website takeover
    • More than 100,000 websites are at risk

    Almost immediately after being disclosed to the public, a vulnerability in a WordPress plugin was used in an attack, security researchers have warned.

    Earlier this week, security outfit Wordfence disclosed an authentication bypass in OttoKit, the all-in-one workflow authentication platform. The vulnerability is tracked as CVE-2025-3102, and was given a severity score 8.1/10 (high).

    https://cdn.mos.cms.futurecdn.net/yDX5VaYZa9C9jFuEEHgxiD-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img