PT-2025-46266 · WordPress · Crypto++

CVE-2025-11986

·

Publicado

2025-11-11

·

Atualizado

2025-11-11

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Crypto plugin for WordPress versions prior to 2.23
Description The software is susceptible to information exposure due to an unauthenticated AJAX action, wp ajax nopriv crypto connect ajax process, which allows calling the register and savenft methods with only a nonce check and no wallet signature verification. This enables unauthenticated attackers to establish a site-wide global authentication state using a transient, bypassing access controls for all site visitors. This results in a complete bypass of shortcode restrictions and page-level access controls, impacting all visitors for approximately one hour, and allows for arbitrary data injection into the custom users table.
Recommendations Update to version 2.23 or later.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-11986

Produtos afetados

Crypto++