CVE detail
CVE-2025-27007
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- 12th May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 12th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The UK’s Legal Aid Agency has suffered a cyberattack. The agency, which operates under the Ministry of Justice to provide billions in legal aid funding, has stated that financial information relating to […]
vendorresearch.checkpoint.comMay 12, 2025, 1:53 PM Threat actors are targeting a critical-severity vulnerability in the OttoKit WordPress plugin to gain administrative privileges.
newswww.securityweek.comMay 7, 2025, 9:01 AMOn May 2nd, 2025 the Wordfence Threat Intelligence team added a new critical vulnerability to the Wordfence Intelligence vulnerability database in the OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin publicly disclosed by a third-party CNA on April 30th, 2025. This vulnerability makes it possible for unauthenticated attackers to gain administrative level access to vulnerable sites, where the site has never used an application password nor connected to SureTriggers or by authenticated attackers with a valid application password.
vendorwww.wordfence.comMay 6, 2025, 4:02 PMNo excerpt available.
Exploitpatchstack.comMay 1, 2025, 11:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-58435CVSS N/A · Unrated
Gitea LFS Deploy-Key Privilege Escalation
- CVE-2026-66661CVSS 7.7 · High
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
- CVE-2026-66424CVSS 9.8 · Critical
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
- CVE-2026-61979CVSS 8.1 · High
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
- CVE-2026-28161CVSS 8.8 · High
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
- CVE-2026-27543CVSS 8.1 · High
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.