CVE-2024-8943

LatePoint <= 5.0.12 - Authentication Bypass

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. Note that logging in as a WordPress user is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability is partially patched in version 5.0.12 and fully patched in version 5.0.13.


We have discovered 683 live websites that are affected by CVE-2024-8943.

Run a Free Instant Scan




Affected Software

Product  LatePoint
Category Wordpress Plugins
Vulnerable Domains683 live websites (100% of LatePoint install base)
Vulnerable Versions
  • from 0 through 5.0.12
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Oct 8, 2024
  • Updated - Oct 8, 2024

Credits

  • István Márton (finder)

Website Distribution by Country

Number of websites using CVE-2024-8943
United States137 websites



Italy70 websites
Germany50 websites
GB50 websites
France49 websites
Spain26 websites
India25 websites
Turkey17 websites
Cyprus17 websites
Netherlands16 websites

Website Distribution by TLD

Number of websites using CVE-2024-8943
.com277 websites
.it64 websites
.co.uk25 websites
.fr19 websites
.de18 websites
.org13 websites
.es12 websites
.nl11 websites
.pl10 websites
.io9 websites

Websites affected by CVE-2024-8943

Top websites that are affected by CVE-2024-8943. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.io United States***,***
********.com United States*,***,***
***************.com Italy*,***,***
**************.com Germany*,***,***
***************.***.uk GB*,***,***
******.*********.com United States*,***,***
*****.com United States*,***,***
***************.com United States*,***,***
******.***************.com France*,***,***
********.com United States*,***,***
See full domain list

FAQ

CVE-2024-8943 is Authentication Bypass Using an Alternate Path or Channel in LatePoint
A total of 683 websites have been identified as vulnerable to CVE-2024-8943, based on global website indexing conducted by WebTechSurvey.
The LatePoint is affected by the CVE-2024-8943 vulnerability.
LatePoint versions up to and including 5.0.12 are vulnerable to CVE-2024-8943.