Impact
The OttoKit plugin versions up to 1.1.35 contain an unauthenticated Server Side Request Forgery flaw that allows an attacker to instruct the plugin to make outbound HTTP requests to arbitrary URLs. This can lead to disclosure of internal network resources, credential theft, or further exploitation of vulnerable services. The weakness corresponds to CWE‑918.
Affected Systems
The vulnerability affects WordPress sites that have the OttoKit plugin installed, specifically Brainstorm Force OttoKit versions 1.1.35 and earlier. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, yet the EPSS score is not available, suggesting limited publicly reported exploitation data. The issue is not catalogued in CISA KEV, implying no known widespread attacks yet. The attack vector is likely available to any user able to reach the plugin’s endpoints because the flaw does not require authentication.
OpenCVE Enrichment