CVE-2024-9989

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due a to limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.
Configurations

Configuration 1 (hide)

cpe:2.3:a:odude:crypto_tool:*:*:*:*:*:wordpress:*:*

History

07 Nov 2024, 17:00

Type Values Removed Values Added
First Time Odude crypto Tool
Odude
CPE cpe:2.3:a:odude:crypto_tool:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L138 - () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L138 - Product
References () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L33 - () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L33 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/e21bd924-1d96-4371-972a-5c99d67261cc?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/e21bd924-1d96-4371-972a-5c99d67261cc?source=cve - Third Party Advisory

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) El complemento Crypto para WordPress es vulnerable a la omisión de autenticación en versiones hasta la 2.15 incluida. Esto se debe a una llamada de método arbitrario limitada a la función 'crypto_connect_ajax_process::log_in' en la función 'crypto_connect_ajax_process'. Esto hace posible que atacantes no autenticados inicien sesión como cualquier usuario existente en el sitio, como un administrador, si tienen acceso al nombre de usuario.

29 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 17:15

Updated : 2024-11-07 17:00


NVD link : CVE-2024-9989

Mitre link : CVE-2024-9989

CVE.ORG link : CVE-2024-9989


JSON object : View

Products Affected

odude

  • crypto_tool
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel