The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://aramhairchitects.nl/ | Not Applicable |
https://aramhairchitects.nl/ | Not Applicable |
https://wpdocs.latepoint.com/changelog/ | Product Release Notes |
https://wpdocs.latepoint.com/changelog/ | Product Release Notes |
https://www.wordfence.com/threat-intel/vulnerabilities/id/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d?source=cve | Third Party Advisory |
https://www.wordfence.com/threat-intel/vulnerabilities/id/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d?source=cve | Third Party Advisory |
Configurations
History
20 Feb 2025, 15:28
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
References | () https://aramhairchitects.nl/ - Not Applicable | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d?source=cve - Third Party Advisory | |
References | () https://wpdocs.latepoint.com/changelog/ - Product, Release Notes | |
First Time |
Latepoint latepoint
Latepoint |
|
CPE | cpe:2.3:a:latepoint:latepoint:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-639 |
14 Jun 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-14 10:15
Updated : 2025-02-20 15:28
NVD link : CVE-2024-2472
Mitre link : CVE-2024-2472
JSON object : View
Products Affected
latepoint
- latepoint
CWE
CWE-639
Authorization Bypass Through User-Controlled Key