PT-2024-16156 · WordPress · Ce21 Suite

István Márton

·

Published

2024-11-08

·

Updated

2025-01-29

·

CVE-2024-10284

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CE21 Suite plugin for WordPress versions up to, and including, 2.2.0
Description The issue is due to a hardcoded encryption key in the ce21 authentication phrase function, allowing unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Recommendations For CE21 Suite plugin for WordPress versions up to, and including, 2.2.0, consider disabling the ce21 authentication phrase function until a patch is available to prevent exploitation. Restrict access to sensitive areas of the site to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-10284

Affected Products

Ce21 Suite