Authentication Bypass Vulnerability in WordPress Crypto Plugin
CVE-2024-9989
What is CVE-2024-9989?
The Crypto plugin for WordPress has a significant security flaw that allows unauthenticated attackers to bypass authentication protocols. This vulnerability stems from a limited arbitrary method call in the 'crypto_connect_ajax_process::log_in' function, which does not properly verify user credentials before permitting access. As a result, attackers can potentially gain unauthorized access as any user, including administrators, by simply knowing the target username. This flaw emphasizes the importance of keeping plugins updated to protect user data and site integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
92% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published