Description
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
Published: 2025-05-01
Score: 9.8 Critical
EPSS: 81.5% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified flaw is an Incorrect Privilege Assignment vulnerability that allows an attacker to elevate privileges within the WordPress site. The weakness is classified as CWE-266, indicating that role or privilege levels are not correctly enforced in the OttoKit plugin. A successful exploitation could lead to an attacker gaining administrative rights, with full control over site content and configuration, compromising confidentiality, integrity, and availability of the web application.

Affected Systems

WordPress sites running Brainstorm Force OttoKit up to and including version 1.0.82 are affected. All installations of the plugin in these versions inherit the privilege escalation flaw. Versions newer than 1.0.82 are assumed to have the issue addressed, though exact version applicability is not listed beyond the upper bound.

Risk and Exploitability

The CVSS score of 9.8 signals that this vulnerability is of critical severity, while an EPSS score of 81% indicates a very high likelihood that exploits are actively available or will be soon. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an authenticated user with lower privileges can use the plugin to elevate themselves to an administrator or other high‑privilege role; a remote attacker who can gain access to a WordPress account could therefore leverage this flaw.

Generated by OpenCVE AI on May 1, 2026 at 09:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the OttoKit plugin to version 1.0.83 or later, which contains the privilege‑assignment fix.
  • If an upgrade cannot be applied immediately, remove the OttoKit plugin entirely to eliminate the risk.
  • Enforce the principle of least privilege in WordPress by limiting user roles to the minimum necessary and auditing accounts for unauthorized administrative rights.

Generated by OpenCVE AI on May 1, 2026 at 09:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allows Privilege Escalation.This issue affects SureTriggers: from n/a through 1.0.82. Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 05 May 2025 14:00:00 +0000


Thu, 01 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 May 2025 11:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allows Privilege Escalation.This issue affects SureTriggers: from n/a through 1.0.82.
Title WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:46.411Z

Reserved: 2025-02-17T11:52:15.089Z

Link: CVE-2025-27007

cve-icon Vulnrichment

Updated: 2025-05-01T14:10:14.785Z

cve-icon NVD

Status : Deferred

Published: 2025-05-01T11:15:54.517

Modified: 2026-04-23T15:26:14.197

Link: CVE-2025-27007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:00:12Z

Weaknesses