Unauthenticated SQL Injection Vulnerability Affects WordPress Users
CVE-2024-8911
9.8CRITICAL
What is CVE-2024-8911?
The LatePoint plugin for WordPress features a security vulnerability due to improper handling of user input, leading to an SQL Injection flaw. This vulnerability allows malicious actors to change user passwords without authentication, particularly affecting WordPress users if the 'Use WordPress users as customers' setting is enabled. When this setting is configured, attackers could manipulate the SQL queries, resulting in unauthorized access to user accounts, including potential control over administrator credentials. The risk emphasizes the importance of securing plugin settings and ensuring timely updates to maintain website integrity.
Affected Version(s)
LatePoint Plugin * <= 5.0.11