PT-2025-47693 · WordPress · Checkbox Plugin

Abhirup Konwar

·

Published

2025-11-21

·

Updated

2025-11-21

·

CVE-2025-12170

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Checkbox plugin for WordPress versions up to and including 2.8.10
Description The Checkbox plugin for WordPress has a flaw that allows unauthorized loss of data. This is due to a missing capability check on the wp ajax nopriv checkbox clean log API endpoint. This allows unauthenticated attackers to clear log files.
Recommendations Update the Checkbox plugin to a version newer than 2.8.10.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12170

Affected Products

Checkbox Plugin