
🚨 CVE-2024-9989: Crypto <= 2.18 - Authentication B... WordPress Crypto plugin's arbitrary method call lets attackers bypass auth with just a username - instant admin takeover... https://zerodaysignal.com/vulnerability/CVE-2024-9989 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post discloses CVE-2024-9989, detailing an authentication bypass via arbitrary method calls in the WordPress Crypto plugin that allows instant admin takeover, but does not mention patches or exploitation tools.
