CVE-2024-2472: Latepoint
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.
Affected products
- Latepoint Latepoint: before 4.9.91 (fixed in 4.9.91)
Published 2024-06-14. Last modified 2026-06-17.