CVE-2024-9988

T

he Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

Configurations

Configuration 1 (hide)

cpe:2.3:a:odude:crypto_tool:*:*:*:*:*:wordpress:*:*

History

07 Nov 2024, 17:00

Type Values Removed Values Added
First Time Odude
Odude crypto Tool
CPE cpe:2.3:a:odude:crypto_tool:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L91 - () https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L91 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/7bfe87cf-9883-4f8f-a0f5-23bbc7bb9b7c?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/7bfe87cf-9883-4f8f-a0f5-23bbc7bb9b7c?source=cve - Third Party Advisory

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) El complemento Crypto para WordPress es vulnerable a la omisión de autenticación en versiones hasta la 2.15 incluida. Esto se debe a la falta de validación del usuario que se proporciona en la función 'crypto_connect_ajax_process::register'. Esto hace posible que atacantes no autenticados inicien sesión como cualquier usuario existente en el sitio, como un administrador, si tienen acceso al nombre de usuario.

29 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 17:15

Updated : 2024-11-07 17:00


NVD link : CVE-2024-9988

Mitre link : CVE-2024-9988

CVE.ORG link : CVE-2024-9988


JSON object : View

Products Affected
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel