CVE-2024-9990

The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Configurations

Configuration 1 (hide)

cpe:2.3:a:odude:crypto_tool:*:*:*:*:*:wordpress:*:*

History

06 Nov 2024, 23:11

Type Values Removed Values Added
First Time Odude crypto Tool
Odude
References () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L31 - () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L31 - Product
References () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L65 - () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L65 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/cea39157-94aa-4982-983e-9c3e4b1af86d?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/cea39157-94aa-4982-983e-9c3e4b1af86d?source=cve - Third Party Advisory
CPE cpe:2.3:a:odude:crypto_tool:*:*:*:*:*:wordpress:*:*

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) El complemento Crypto para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 2.15 incluida. Esto se debe a la falta de validación de nonce en la función 'crypto_connect_ajax_process::check'. Esto hace posible que atacantes no autenticados inicien sesión como cualquier usuario existente en el sitio, como un administrador a través de una solicitud falsificada, siempre que puedan engañar a un administrador del sitio para que realice una acción como hacer clic en un enlace.

29 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 17:15

Updated : 2024-11-06 23:11


NVD link : CVE-2024-9990

Mitre link : CVE-2024-9990

CVE.ORG link : CVE-2024-9990


JSON object : View

Products Affected

odude

  • crypto_tool
CWE
CWE-352

Cross-Site Request Forgery (CSRF)