The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Feb 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Latepoint
Latepoint latepoint |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:latepoint:latepoint:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Latepoint
Latepoint latepoint |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T19:11:53.521Z
Reserved: 2024-03-14T20:16:46.611Z
Link: CVE-2024-2472

Updated: 2024-08-01T19:11:53.521Z

Status : Analyzed
Published: 2024-06-14T10:15:09.403
Modified: 2025-02-20T15:28:10.360
Link: CVE-2024-2472

No data.