Extension WordPress

Vulnérabilités Crypto

Cette page rassemble les failles publiées pour Crypto, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
2Critiques
3Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Crypto

5 fiches

CVE-2025-11986 Moyenne · 5,3
Crypto

Crypto Tool <= 2.22 – Unauthenticated Information Exposure via Global Authentication State

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft methods…

Versions affectées

*-2.22

Correctif

Non indiqué

Publication

10/11/2025

CVE-2025-11988 Moyenne · 5,3
Crypto

Crypto Tool <= 2.22 – Missing Authentication to Unauthenticated Limited File Deletion

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method…

Versions affectées

*-2.22

Correctif

Non indiqué

Publication

10/11/2025

CVE-2024-9989 Critique · 9,8
Crypto

Crypto <= 2.18 – Authentication Bypass via log_in

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for…

Versions affectées

*-2.18

Correctif

2.19

Publication

28/10/2024

CVE-2024-9988 Critique · 9,8
Crypto

Crypto <= 2.19 – Authentication Bypass via register

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated…

Versions affectées

*-2.19

Correctif

2.20

Publication

28/10/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités