CVE-2025-11771

⚪ Do wiadomości

Brak uwierzytelnienia w wtyczce TokenICO pozwala nieautoryzowanym atakującym na manipulację danymi.

CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'createSaleRecord' function in all versions up to, and including, 2.4.7. This makes it possible for unauthenticated attackers to manipulate presales counters.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-11-21 08:15:50 UTC
Ostatnia modyfikacja (NVD)2026-10-07 21:10:00 UTC
Referencje