Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.7 - Missing Authentication to Unauthenticated Presale Update
Strategic Overview
<= 2.4.7CVE-2025-11771Vulnerability Overview
The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'createSaleRecord' function in all versions up to, and including, 2.4.7. This makes it possible for unauthenticated attackers to manipulate presales counters.
Technical Analysis
REMEDIATION: Update to version 2.4.8, or a newer patched version --- IDENTIFIER: CWE-306 (Missing Authentication for Critical Function) The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C