PT-2025-47681 · WordPress · Cryptocurrency (Token)

Published

2025-11-21

·

Updated

2025-11-21

·

CVE-2025-11771

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress versions through 2.4.6
Description The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is susceptible to unauthorized data modification. This is due to the absence of authentication and capability checks within the createSaleRecord() function. An unauthenticated attacker can manipulate presale counters.
Recommendations Update the Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress to a version beyond 2.4.6.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-11771

Affected Products

Cryptocurrency (Token)