The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-available nonce check. This makes it possible for unauthenticated attackers to delete specific JSON files matching the pattern *_pending.json within the wp-content/uploads/yak/ directory, causing data loss and denial of service for plugin workflows that rely on these artifacts.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Odude
Odude crypto Tool Wordpress Wordpress wordpress |
|
| Vendors & Products |
Odude
Odude crypto Tool Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-available nonce check. This makes it possible for unauthenticated attackers to delete specific JSON files matching the pattern *_pending.json within the wp-content/uploads/yak/ directory, causing data loss and denial of service for plugin workflows that rely on these artifacts. | |
| Title | Crypto Tool <= 2.22 - Missing Authentication to Unauthenticated Limited File Deletion | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-11T03:30:35.177Z
Updated: 2025-11-12T20:08:35.294Z
Reserved: 2025-10-20T19:32:02.759Z
Link: CVE-2025-11988
Updated: 2025-11-12T17:02:03.202Z
Status : Awaiting Analysis
Published: 2025-11-11T04:15:44.967
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-11988
No data.