Description

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. Note that logging in as a WordPress user is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability is partially patched in version 5.0.12 and fully patched in version 5.0.13.

INFO

Published Date :

2024-10-08T08:33:18.812Z

Last Modified :

2026-04-08T17:18:20.362Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8943 vulnerability.

Vendors Products
Latepoint
  • Latepoint
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-8943.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact