plugin

Tnc Toolbox Vulnerabilities

4 known security issues reported for the Tnc Toolbox WordPress plugin. Most recent disclosed Nov 29, 2025.

1 critical 1 medium

Running Tnc Toolbox on your site? Check whether your installed version is affected.

Scan your site free

TNC Toolbox: Web Performance <= 2.0.4 - Missing Authorization

medium

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Nov 29, 2025

CVE-2025-66108 on NVD →

TNC Toolbox: Web Performance [tnc-toolbox] <= 2.0.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.

Affected:
up to 2.0.4
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66108 on NVD →

TNC Toolbox: Web Performance [tnc-toolbox] < 2.0.0

unknown

[en] The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate prot...

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Nov 11, 2025

CVE-2025-12539 on NVD →

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

critical

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate protectio...

CVSS:
10
Affected:
up to 1.4.2
Fixed in:
2.0.0
Disclosed:
Nov 10, 2025

CVE-2025-12539 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database