Unauthenticated SQL Injection Vulnerability Affects WordPress Users
CVE-2024-8911

9.8CRITICAL

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
8 October 2024

Summary

The LatePoint plugin for WordPress features a security vulnerability due to improper handling of user input, leading to an SQL Injection flaw. This vulnerability allows malicious actors to change user passwords without authentication, particularly affecting WordPress users if the 'Use WordPress users as customers' setting is enabled. When this setting is configured, attackers could manipulate the SQL queries, resulting in unauthorized access to user accounts, including potential control over administrator credentials. The risk emphasizes the importance of securing plugin settings and ensuring timely updates to maintain website integrity.

Affected Version(s)

LatePoint Plugin * <= 5.0.11

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.