The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:pedalo:pedalo_connector:*:*:*:*:*:wordpress:*:* |
Fri, 11 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pedalo
Pedalo pedalo Connector |
|
CPEs | cpe:2.3:a:pedalo:pedalo_connector:*:*:*:*:*:*:*:* | |
Vendors & Products |
Pedalo
Pedalo pedalo Connector |
|
Metrics |
ssvc
|
Fri, 11 Oct 2024 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator. | |
Title | Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-11T02:32:46.048Z
Updated: 2024-10-11T14:52:04.050Z
Reserved: 2024-10-10T14:26:24.860Z
Link: CVE-2024-9822
Vulnrichment
Updated: 2024-10-11T14:51:59.371Z
NVD
Status : Analyzed
Published: 2024-10-11T03:15:10.967
Modified: 2024-11-15T16:41:41.507
Link: CVE-2024-9822
Redhat
No data.