PT-2025-47693 · WordPress · Checkbox Plugin

·

CVE-2025-12170

·

Published

2025-11-21

·

Updated

2025-11-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Checkbox plugin for WordPress versions up to and including 2.8.10
Description The Checkbox plugin for WordPress has a flaw that allows unauthorized loss of data. This is due to a missing capability check on the wp ajax nopriv checkbox clean log API endpoint. This allows unauthenticated attackers to clear log files.
Recommendations Update the Checkbox plugin to a version newer than 2.8.10.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12170

Affected Products

Checkbox Plugin