The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 26 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Latepoint latepoint Plugin
|
|
| CPEs | cpe:2.3:a:latepoint:latepoint_plugin:4.9.9:*:*:*:*:*:*:* | |
| Vendors & Products |
Latepoint latepoint Plugin
|
|
| Metrics |
ssvc
|
Thu, 20 Feb 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Latepoint
Latepoint latepoint |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:latepoint:latepoint:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Latepoint
Latepoint latepoint |
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-06-14T09:36:37.719Z
Updated: 2026-04-08T16:56:57.971Z
Reserved: 2024-03-14T20:16:46.611Z
Link: CVE-2024-2472
Updated: 2024-08-01T19:11:53.521Z
Status : Modified
Published: 2024-06-14T10:15:09.403
Modified: 2026-04-08T18:21:06.270
Link: CVE-2024-2472
No data.