{"id":"CVE-2025-11196","title":"The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX action lacking capability checks or nonce validation","summary":"The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX action lacking capability checks or nonce validation. This makes…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"published":"2025-10-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11196","references":[{"url":"https://plugins.trac.wordpress.org/browser/external-login/trunk/login/db.php#L215","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/external-login/trunk/options/testing_ajax.php#L3","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/external-login/trunk/views/test_results.php#L21","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bdb40f51-dac2-40e7-beb1-154d982f7af3?source=cve","label":"security@wordfence.com"}],"tags":["nvd"],"epss":0.00269,"epssPercentile":0.17468,"ingestedAt":"2026-10-08T11:31:27.427Z","slug":"CVE-2025-11196","body":"## Overview\n\nThe External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.11.2 due to the 'exlog_test_connection' AJAX action lacking capability checks or nonce validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to query the configured external database and retrieve truncated usernames, email addresses, and password hashes via the diagnostic test results view.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}