WordPress Plugin Vulnerabilities

LatePoint Plugin < 4.9.9.1 - Missing Authorization and Sensitive Information Exposure via IDOR

Description

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.

Affects Plugins

Fixed in 4.9.9.1

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Gharib Sharifi, Joel Aviad Ossi
Verified
No

Timeline

Publicly Published
2024-06-13 (about 1 year ago)
Added
2024-06-13 (about 1 year ago)
Last Updated
2024-06-14 (about 1 year ago)

Other