{
    "id": "CVE-2024-9989",
    "published": "2024-10-29 17:15:05",
    "last_modified": "2026-06-17 08:25:39",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-288",
    "description": "The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.",
    "epss_score": "0.07112",
    "epss_percentile": "0.94063",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-05 18:17:41",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "odude",
            "product": "crypto_tool"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L138",
        "https://plugins.trac.wordpress.org/browser/crypto/tags/2.10/includes/class-crypto_connect_ajax_register.php#L33",
        "https://plugins.trac.wordpress.org/changeset/3189945/crypto#file3",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/e21bd924-1d96-4371-972a-5c99d67261cc?source=cve"
    ]
}