S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 7, 2025

CVE-2024-9989 Scanner

CVE-2024-9989 Scanner - Authentication Bypass vulnerability in Crypto

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9989
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Crypto Toolby odude
0
cryptoby odude
0
Updated Sep 10, 2026View on NVD →
Detail

The Crypto plugin is widely used in WordPress environments, particularly for sites dealing with cryptocurrency and related data. The plugin is designed to provide enhanced security and functionality for WordPress installations by offering various cryptographic tools and methods. Developed by Odude, it caters to both individual users and large organizations who want to secure transactions and communications. Due to its popularity, any vulnerabilities within the plugin can affect a wide range of websites and users. Moreover, WordPress is one of the most widely used content management systems, increasing the potential risk and reach of this vulnerability.

The vulnerability in question allows for authentication bypass within the Crypto plugin version 2.15 and earlier. This exploit is particularly critical as it permits unauthorized users to log in as existing members of a WordPress site. What makes this vulnerability significant is that attackers can gain administrator privileges without actual user credentials. Detection and mitigation of this vulnerability are crucial to safeguarding website integrity and user privacy.

Technically, the vulnerability arises from an arbitrary method call to the 'crypto_connect_ajax_process::log_in' function within the 'crypto_connect_ajax_process'. This technical flaw is indicative of improper input validation, enabling attackers to manipulate the AJAX processes to bypass standard authentication checks. The flawed endpoint potentially allows access control vulnerabilities in affected installations, making it imperative to identify and patch any susceptible installations.

Exploitation of this vulnerability could have several detrimental effects. Unauthorized access can lead to data loss, theft of sensitive information, and loss of control over the WordPress site. An attacker could modify website content, deface pages, or install malware, affecting business operations and reputations. The risk of unauthorized administrator access can disrupt site functionality and lead to significant operational and financial damages.

Solution Advice
  • Update the Crypto plugin to the latest version to patch the vulnerability and prevent unauthorized access.
  • Implement additional security measures such as multi-factor authentication (MFA) to enhance user authentication processes.
  • Regularly review and audit user access logs to detect any unauthorized login attempts or dubious activity.
  • Educate users about the importance of strong, unique passwords to increase the overall security posture of the WordPress environment.
  • Employ a web application firewall (WAF) to mitigate exploitation attempts and halt potentially malicious traffic directed at your site.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.