Crypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication State
medium
The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft methods with only a publicly-available nonce ch...
- CVSS:
- 5.3
- Affected:
- up to 2.22
- Fixed in:
- 3.0.0
- Disclosed:
- Nov 10, 2025
CVE-2025-11986 on NVD →
Crypto Tool <= 2.22 - Missing Authentication to Unauthenticated Limited File Deletion
medium
The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-availabl...
- CVSS:
- 5.3
- Affected:
- up to 2.22
- Fixed in:
- 3.0.0
- Disclosed:
- Nov 10, 2025
CVE-2025-11988 on NVD →
Crypto <= 2.19 - Authentication Bypass via register
critical
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the...
- CVSS:
- 9.8
- Affected:
- up to 2.19
- Fixed in:
- 2.20
- Disclosed:
- Oct 28, 2024
CVE-2024-9988 on NVD →
Crypto <= 2.18 - Authentication Bypass via log_in
critical
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as...
- CVSS:
- 9.8
- Affected:
- up to 2.18
- Fixed in:
- 2.19
- Disclosed:
- Oct 28, 2024
CVE-2024-9989 on NVD →
Crypto <= 2.15 - Cross-Site Request Forgery to Authentication Bypass
high
The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an ad...
- CVSS:
- 8.8
- Affected:
- up to 2.15
- Fixed in:
- 2.16
- Disclosed:
- Oct 28, 2024
CVE-2024-9990 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database