Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-9822 — Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator | Kitploit
Tools/GitHubGitHub/randomrobbiebf/cve-2024-9822
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubrandomrobbiebf/cve-2024-9822

CVE-2024-9822

Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-9822

Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator

Description

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.

root@kitploit:~
Type: plugin
CVSS Score: 9.8
CVE: CVE-2024-9822
Slug: pedalo-connector

Download Link: Download pedalo-connector Version 2.0.5

POC

root@kitploit:~
/?dd=1

Needs the Pedalo Connector activated and have the site health thing running. if it's not connected correctly you just get redirected to the login page with the admin username.

Download Tool