Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Odude
Odude crypto Tool Wordpress Wordpress wordpress |
|
| Vendors & Products |
Odude
Odude crypto Tool Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft methods with only a publicly-available nonce check and no wallet signature verification. This makes it possible for unauthenticated attackers to set a site-wide global authentication state via a single transient, bypassing all access controls for ALL visitors to the site. The impact is complete bypass of [crypto-block] shortcode restrictions and page-level access controls, affecting all site visitors for one hour, plus the ability to inject arbitrary data into the plugin's custom_users table. | |
| Title | Crypto Tool <= 2.22 - Unauthenticated Information Exposure via Global Authentication State | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:32:13.715Z
Reserved: 2025-10-20T18:56:32.332Z
Link: CVE-2025-11986
Updated: 2025-11-12T15:10:35.365Z
Status : Deferred
Published: 2025-11-11T04:15:44.780
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11986
No data.
OpenCVE Enrichment
Updated: 2026-04-21T18:30:27Z