PT-2025-46266 · WordPress · Crypto++
CVE-2025-11986
·
Publicado
2025-11-11
·
Atualizado
2025-11-11
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Crypto plugin for WordPress versions prior to 2.23
Description
The software is susceptible to information exposure due to an unauthenticated AJAX action,
wp ajax nopriv crypto connect ajax process, which allows calling the register and savenft methods with only a nonce check and no wallet signature verification. This enables unauthenticated attackers to establish a site-wide global authentication state using a transient, bypassing access controls for all site visitors. This results in a complete bypass of shortcode restrictions and page-level access controls, impacting all visitors for approximately one hour, and allows for arbitrary data injection into the custom users table.Recommendations
Update to version 2.23 or later.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Crypto++