CVE-2024-9822 describes an authentication bypass vulnerability in the Pedalo Connector plugin for WordPress, affecting versions up to and including 2.0.5. This flaw stems from insufficient restrictions on the 'login_admin_user' function, allowing unauthenticated attackers to log in as the first registered user, typically an administrator. The vulnerability carries a critical CVSS score of 9.8, indicating a network-exploitable flaw with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While the EPSS score suggests a moderate likelihood of exploitation, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.5CPE matchmatch criteria | cpe:2.3:a:pedalo:pedalo_connector:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.