SureTriggers WordPress Plugin Authentication Bypass Vulnerability Allowing Unauthenticated Administrative User Creation

Vulnerability

A vulnerability exists in the SureTriggers: All-in-One Automation Platform plugin for WordPress, in versions through and including 1.0.78. The issue arises from an authentication bypass that allows unauthenticated attackers to create administrative accounts on the target website. This vulnerability is due to a missing empty value check on the 'secret_key' in the 'autheticate_user' function. The flaw is exploitable when the plugin is installed and activated but not configured with an API key.

Impact

Exploitation of this vulnerability allows for unauthorized creation of administrative accounts on the affected WordPress site.

Remediation

Users can update to version 1.0.79 or a newer patched version to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
5.0
exploitability
8.2
remediation
7.7
relevance
0.0
threat
4.9
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.