LatePoint <= 5.0.12 - Authentication Bypass
CVE-2024-8943
Verified
Description
LatePoint plugin for WordPress versions up to 5.0.12 contains an authentication bypass caused by insufficient verification of user during booking, letting unauthenticated attackers log in as any existing user if they have user ID access, exploit requires access to user ID, and the 'Use WordPress users as customers' setting enabled.
Severity
Critical
CVSS Score
9.8
Exploit Probability
3%
Affected Product
latepoint
Published Date
February 4, 2026
Template Author
daffainfo
CVE-2024-8943.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-8943
CWE ID:
cwe-287
References
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/LatePoint/latepoint-5012-authentication-bypasshttps://www.wordfence.com/blog/2024/10/7000-wordpress-sites-affected-by-unauthenticated-critical-vulnerabilities-in-latepoint-wordpress-plugin/https://nvd.nist.gov/vuln/detail/CVE-2024-8943
Remediation Steps
Update to version 5.0.13 or later.