CVE-2025-66108: WordPress TNC Toolbox: Web Performance plugin <= 2.0.4 - Broken Access Control vulnerability
Published Nov 21, 2025
·Updated
Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.
Affected Software
2 affected components
TNC Toolbox: Web Performance<=2.0.4
WordPress TNC Toolbox: Web Performance<=2.0.4
Event History
Nov 21, 2025
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66108?
CVE-2025-66108 has a high severity rating due to its potential for unauthorized access.
2
How do I fix CVE-2025-66108?
To fix CVE-2025-66108, update TNC Toolbox: Web Performance to version 2.0.5 or later.
3
What type of vulnerability is CVE-2025-66108?
CVE-2025-66108 is a Missing Authorization vulnerability related to incorrectly configured access control.
4
Which software versions are affected by CVE-2025-66108?
CVE-2025-66108 affects TNC Toolbox: Web Performance versions up to and including 2.0.4.
5
What can happen if CVE-2025-66108 is exploited?
If exploited, CVE-2025-66108 could allow an attacker to gain unauthorized access to restricted functionalities.