CVE · Critical

CVE-2024-2472 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 4.9.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2472 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 4.9.9.1 Authorization Bypass Through User-Controlled Key Critical 9.1 < 4.9.9.1 4.9.9.1 2024-06-13

CVE-2024-2472

The LatePoint plugin for WordPress contains a capability check vulnerability in the 'start_or_use_session_for_customer' function that affects versions up to 4.9.9, allowing unauthenticated attackers to access and modify customer data without authorization. Attackers can view other customers' accounts and personally identifiable information like email addresses, as well as reset LatePoint user passwords regardless of whether those accounts are linked to WordPress user profiles.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.