Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High2
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-06-17

CVE-2026-4935 - All In One Automation Platform Plugin

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

PLUGIN All In One Automation Platform

CVE-2026-4935

HIGH CVSS 8.6 2026-05-08
Threat Entry Updated 2025-04-11

CVE-2025-3102 - All In One Automation Platform Plugin

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

PLUGIN All In One Automation Platform

CVE-2025-3102

HIGH CVSS 8.1 2025-04-10
Scroll to top