Unauthenticated SQL Injection Vulnerability Affects WordPress Users
CVE-2024-8911
9.8CRITICAL
Summary
The LatePoint plugin for WordPress features a security vulnerability due to improper handling of user input, leading to an SQL Injection flaw. This vulnerability allows malicious actors to change user passwords without authentication, particularly affecting WordPress users if the 'Use WordPress users as customers' setting is enabled. When this setting is configured, attackers could manipulate the SQL queries, resulting in unauthorized access to user accounts, including potential control over administrator credentials. The risk emphasizes the importance of securing plugin settings and ensuring timely updates to maintain website integrity.
Affected Version(s)
LatePoint Plugin * <= 5.0.11
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton