Executive brief
OttoKit (also known as suretriggers) is a WordPress plugin used for automation and connecting different web services. A security vulnerability in this plugin allows an attacker with administrative access to perform blind SQL injection. This could lead to the unauthorized extraction of sensitive information from the website's database, potentially compromising user data or site configuration.
Technical details
A blind SQL injection vulnerability exists in the Brainstorm Force OttoKit (suretriggers) plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw allows an authenticated attacker with high privileges (Administrator) to execute arbitrary SQL queries against the backend database via a network request. While the attack requires administrative credentials, the 'Scope' change in the CVSS vector suggests the impact may extend beyond the plugin's immediate environment. Attackers can leverage this to extract sensitive data from the database. The issue is fixed in version 1.1.21.
Affected products
- Brainstorm Force OttoKit (suretriggers) <= 1.1.20
Timeline
- 2026-02-21: disclosed: Reported by timomangcut to Patchstack
- 2026-03-23: advisory: Patchstack published advisory
- 2026-04-08: advisory: CVE published to NVD
- 2026-03-23: patched: Fixed in version 1.1.21