Cross-Site Request Forgery Vulnerability in WordPress Crypto Plugin
CVE-2024-9990
What is CVE-2024-9990?
The Crypto plugin for WordPress contains a security weakness that exposes it to Cross-Site Request Forgery (CSRF) attacks in all versions 2.15 and below. This vulnerability arises from insufficient nonce validation in the 'crypto_connect_ajax_process::check' function, enabling attackers to exploit the flaw. By tricking a site administrator into executing a crafted action, an unauthenticated attacker could potentially gain access to user accounts, including administrative privileges, through a forged request. Securing your WordPress installation and ensuring all plugins are up to date is critical to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published