---
id: CVE-2025-11988
title: >-
  The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of
  data in all versions up to, and including, 2.22
summary: >-
  The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of
  data in all versions up to, and including, 2.22. This is due to the plugin
  registering an unauthenticated AJAX action
  (wp_ajax_nopriv_crypto_connect_ajax_proce…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2025-11-11'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11988'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/crypto/tags/2.22/includes/class-crypto_connect_ajax_register.php#L137
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/crypto/tags/2.22/includes/class-crypto_connect_ajax_register.php#L9
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/3281d6eb-9f14-43d4-a4d4-532993039e53?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.00339
epssPercentile: 0.24922
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/jFriedli/CVE-2025-11988'
  checkedAt: '2026-09-30T23:30:07.501Z'
exploitAvailable: true
ingestedAt: '2026-09-30T23:29:32.466Z'
---

## Overview

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the crypto_delete_json method with only a publicly-available nonce check. This makes it possible for unauthenticated attackers to delete specific JSON files matching the pattern *_pending.json within the wp-content/uploads/yak/ directory, causing data loss and denial of service for plugin workflows that rely on these artifacts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
