Junglewise Threat Intelligence

CVE-2026-49781: Brainstorm Force OttoKit PHP object injection

CVE-2026-49781 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Vendors: Brainstorm Force.

Executive brief

OttoKit, a WordPress plugin used for automation and integration, contains a critical security flaw that allows unauthorized users to interfere with the site's internal data processing. By exploiting this vulnerability, an attacker could potentially take full control of the website, steal sensitive information, or disrupt services. This type of flaw is frequently targeted in automated mass-exploitation campaigns against WordPress sites.

Technical details

OttoKit (formerly associated with SureTriggers) for WordPress is vulnerable to PHP Object Injection due to improper deserialization of user-supplied input (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, arbitrary file deletion, or unauthorized database access. The vulnerability is patched in version 1.1.28.

Affected products

  • Brainstorm Force OttoKit (SureTriggers) <= 1.1.27

Timeline

  • 2026-05-12: other: Reported by researcher daroo
  • 2026-06-04: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: NVD publication date

References