CVE-2026-4935: Unknown Ottokit: All-In-One Automation Platform

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

Affected products

  • Unknown Ottokit: All-In-One Automation Platform: before 1.1.23 (fixed in 1.1.23)

Published 2026-05-08. Last modified 2026-06-17.