The security issue stems from an authentication bypass in the plugin’s REST API endpoint handling, which fails to properly validate empty secret key values. A critical vulnerability affecting over 100,000 WordPress websites has been discovered in the SureTriggers WordPress plugin, potentially allowing attackers to create unauthorized administrator accounts. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Consequently, when both the plugin’s configured key and the attacker-supplied key are empty, the condition evaluates to true, granting the attacker access to the REST API endpoint. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. When exploited, attackers can leverage this oversight to create administrator accounts without authentication, leading to complete site compromise. The function compares the secret key in the request header with the configured secret key but fails to check for empty values. Through this endpoint, attackers can execute the run_action() function to create administrator accounts without any authentication. Tushar is a Cyber security content editor with a passion for creating captivating and informative content. Once administrative access is gained, malicious actors can upload backdoors, inject malware, redirect users to phishing sites, or insert spam content throughout the affected website. Security researcher mikemyers, who discovered and responsibly reported the issue, received a $1,024 bounty for the finding. Following the discovery, Wordfence promptly notified the plugin’s developer, Brainstorm Force, who released a patched version on April 3rd, 2025. The vulnerability’s technical nature reveals a concerning oversight in the plugin’s security architecture. The issue exists in the autheticate_user() function, which handles permission checks for the plugin’s REST API endpoints.
This Cyber News was published on cybersecuritynews.com. Publication date: Sun, 13 Apr 2025 00:05:03 +0000