CVE-2024-8943

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Feb 20, 2025
CWE ID 306
CWE ID 288

Summary

CVE-2024-8943 is a vulnerability affecting the LatePoint plugin for WordPress. In versions up to and including 5.0.12, there is an authentication bypass issue. This flaw arises from insufficient user verification during the booking customer step, allowing unauthenticated attackers to log in as any existing user on the site, including administrators. However, this exploit is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability is partially addressed in version 5.0.12, but fully patched in the subsequent release, 5.0.13.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share