Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| brainstormforce | OttoKit: All-in-One Automation Platform (Formerly SureTriggers) | * ~ 1.0.78 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | EXPLOIT CVE-2025-3102 | https://github.com/xxmarcosrobertoxx/vanda-CVE-2025-3102 | POC Details |
| 2 | EXPLOIT CVE-2025-3102 | https://github.com/itsismarcos/vanda-CVE-2025-3102 | POC Details |
| 3 | Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation | https://github.com/Nxploited/CVE-2025-3102 | POC Details |
| 4 | Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation | https://github.com/rhz0d/CVE-2025-3102 | POC Details |
| 5 | The SureTriggers- All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-3102.yaml | POC Details |
| 6 | None | https://github.com/dennisec/CVE-2025-3102 | POC Details |
| 7 | Detects the version of the SureTriggers WordPress plugin from exposed asset URLs and compares it to determine if it's vulnerable (<= 1.0.78). | https://github.com/SUPRAAA-1337/CVE-2025-3102 | POC Details |
| 8 | Checks the SureTriggers WordPress plugin's readme.txt file for the Stable tag version. If the version is less than or equal to 1.0.78, it is considered vulnerable.0.78). | https://github.com/SUPRAAA-1337/CVE-2025-3102_v2 | POC Details |
| 9 | Exploitation of an authorization bypass vulnerability in the SureTriggers plugin for WordPress versions <= 1.0.78, allowing unauthenticated attackers to create new WordPress users. | https://github.com/SUPRAAA-1337/CVE-2025-3102-exploit | POC Details |
| 10 | SureTriggers <= 1.0.78 - Authorization Bypass Exploit | https://github.com/0xgh057r3c0n/CVE-2025-3102 | POC Details |
| 11 | The SureTriggers WordPress plugin contains a critical authentication bypass vulnerability (CVE-2025-3102) that affects all versions up to and including 1.0.78. | https://github.com/baribut/CVE-2025-3102 | POC Details |
| 12 | SureTriggers <= 1.0.78 - Authorization Bypass Exploit | https://github.com/zr1p3r/CVE-2025-3102 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet