/Vulnerability Library

LatePoint <= 5.0.12 - Authentication Bypass

CVE-2024-8943
Verified

Description

LatePoint plugin for WordPress versions up to 5.0.12 contains an authentication bypass caused by insufficient verification of user during booking, letting unauthenticated attackers log in as any existing user if they have user ID access, exploit requires access to user ID, and the 'Use WordPress users as customers' setting enabled.

Severity

Critical

CVSS Score

9.8

Exploit Probability

3%

Affected Product

latepoint

Published Date

February 4, 2026

Template Author

daffainfo

CVE-2024-8943.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-8943
CWE ID:
cwe-287

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/LatePoint/latepoint-5012-authentication-bypasshttps://www.wordfence.com/blog/2024/10/7000-wordpress-sites-affected-by-unauthenticated-critical-vulnerabilities-in-latepoint-wordpress-plugin/https://nvd.nist.gov/vuln/detail/CVE-2024-8943

Remediation Steps

Update to version 5.0.13 or later.