CVE-2024-10284

The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encryption key in the 'ce21_authentication_phrase' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ce21:ce21_suite:*:*:*:*:*:wordpress:*:*

History

29 Jan 2025, 18:46

Type Values Removed Values Added
First Time Ce21
Ce21 ce21 Suite
References () https://plugins.trac.wordpress.org/browser/ce21-suite/trunk/single-sign-on-ce21.php?rev=3097700#L242 - () https://plugins.trac.wordpress.org/browser/ce21-suite/trunk/single-sign-on-ce21.php?rev=3097700#L242 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/45d66743-300e-480d-98b8-99dc30b6e786?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/45d66743-300e-480d-98b8-99dc30b6e786?source=cve - Third Party Advisory
CPE cpe:2.3:a:ce21:ce21_suite:*:*:*:*:*:wordpress:*:*
CWE CWE-306

12 Nov 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) El complemento CE21 Suite para WordPress es vulnerable a la omisión de autenticación en versiones hasta la 2.2.0 incluida. Esto se debe a una clave de cifrado codificada en la función 'ce21_authentication_phrase'. Esto permite que atacantes no autenticados inicien sesión como cualquier usuario existente en el sitio, como un administrador, si tienen acceso al correo electrónico.

09 Nov 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-09 03:15

Updated : 2025-01-29 18:46


NVD link : CVE-2024-10284

Mitre link : CVE-2024-10284

CVE.ORG link : CVE-2024-10284


JSON object : View

Products Affected

ce21

  • ce21_suite
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-306

Missing Authentication for Critical Function