CVE-2024-8943
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-8943 is a vulnerability affecting the LatePoint plugin for WordPress. In versions up to and including 5.0.12, there is an authentication bypass issue. This flaw arises from insufficient user verification during the booking customer step, allowing unauthenticated attackers to log in as any existing user on the site, including administrators. However, this exploit is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability is partially addressed in version 5.0.12, but fully patched in the subsequent release, 5.0.13.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.