Medium 5.3
2025-11-21< 2.8.11
CVE-2025-12170
Minimum safe version
2.8.11
Update to 2.8.11 or later to address 5 fixable vulnerabilities
CVE-2025-12170
WordPress Checkbox Plugin <= 0.8.3 is vulnerable to Cross Site Scripting (XSS)
Unauthorised AJAX Calls via Freemius
WordPress Checkbox plugin <= 0.8.3 - Sensitive Information Disclosure vulnerability
WordPress Checkbox plugin <= 0.8.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability