WordPress Plugin Vulnerabilities
LatePoint Plugin < 4.9.9.1 - Missing Authorization and Sensitive Information Exposure via IDOR
Description
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.
Affects Plugins
References
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Gharib Sharifi, Joel Aviad Ossi
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-06-13 (about 1 year ago)
Added
2024-06-13 (about 1 year ago)
Last Updated
2024-06-14 (about 1 year ago)