CVE-2024-9933 POC (Proof-of-Concept)

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user.

Published: 2024-10-26

CVSS: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Download CVE-2024-9933 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check my portfolio here:

https://tlncglobal.com/poc-175-cve-2025-4388/

https://tlncglobal.com/poc-59-cve-2025-6798/

https://tlncglobal.com/poc-935-cve-2024-4701/