plugin

Crypto Vulnerabilities

5 known security issues reported for the Crypto WordPress plugin. Most recent disclosed Nov 10, 2025.

2 critical 1 high 2 medium

Running Crypto on your site? Check whether your installed version is affected.

Scan your site free

Crypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication State

medium

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft methods with only a publicly-available nonce ch...

CVSS:
5.3
Affected:
up to 2.22
Fixed in:
3.0.0
Disclosed:
Nov 10, 2025

CVE-2025-11986 on NVD →

Crypto Tool <= 2.22 - Missing Authentication to Unauthenticated Limited File Deletion

medium

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-availabl...

CVSS:
5.3
Affected:
up to 2.22
Fixed in:
3.0.0
Disclosed:
Nov 10, 2025

CVE-2025-11988 on NVD →

Crypto <= 2.19 - Authentication Bypass via register

critical

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the...

CVSS:
9.8
Affected:
up to 2.19
Fixed in:
2.20
Disclosed:
Oct 28, 2024

CVE-2024-9988 on NVD →

Crypto <= 2.18 - Authentication Bypass via log_in

critical

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as...

CVSS:
9.8
Affected:
up to 2.18
Fixed in:
2.19
Disclosed:
Oct 28, 2024

CVE-2024-9989 on NVD →

Crypto <= 2.15 - Cross-Site Request Forgery to Authentication Bypass

high

The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an ad...

CVSS:
8.8
Affected:
up to 2.15
Fixed in:
2.16
Disclosed:
Oct 28, 2024

CVE-2024-9990 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database