CVE-2025-3102
HIGH EXPLOITED NUCLEISureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
Title source: nucleiDescription
The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.
Exploits (11)
github
WORKING POC
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/WordPress_suretriggers-CVE-2025-3102-AuthenticationBypass.py
nomisec
WORKING POC
3 stars
by itsismarcos · remote
https://github.com/itsismarcos/vanda-CVE-2025-3102
nomisec
WORKING POC
1 stars
by SUPRAAA-1337 · remote
https://github.com/SUPRAAA-1337/CVE-2025-3102-exploit
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-3102
Nuclei Templates (1)
SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication Bypass
HIGHVERIFIEDby DhiyaneshDK
References (3)
Scores
CVSS v3
8.1
EPSS
0.8781
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-04-09
CWE
CWE-697
Status
published
Products (2)
brainstormforce/OttoKit: All-in-One Automation Platform
< 1.0.78
brainstormforce/OttoKit: All-in-One Automation Platform (Formerly SureTriggers)
< 1.0.78
Published
Apr 10, 2025
Tracked Since
Feb 18, 2026