CVE-2024-9822

CRITICAL

Pedalo Connector < 2.0.5 - Authentication Bypass

Title source: rule

Description

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9822

Scores

CVSS v3 9.8
EPSS 0.1462
EPSS Percentile 94.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-288
Status published

Affected Products (1)

pedalo/pedalo_connector < 2.0.5

Timeline

Published Oct 11, 2024
Tracked Since Feb 18, 2026