TNC Toolbox: Web Performance <= 2.0.4 - Missing Authorization
medium
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Nov 29, 2025
CVE-2025-66108 on NVD →
TNC Toolbox: Web Performance [tnc-toolbox] <= 2.0.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.
- Affected:
- up to 2.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66108 on NVD →
TNC Toolbox: Web Performance [tnc-toolbox] < 2.0.0
unknown
[en] The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate prot...
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Nov 11, 2025
CVE-2025-12539 on NVD →
TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover
critical
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate protectio...
- CVSS:
- 10
- Affected:
- up to 1.4.2
- Fixed in:
- 2.0.0
- Disclosed:
- Nov 10, 2025
CVE-2025-12539 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database