Authentication vulnerability in LatePoint Plugin 5.0.12

The LatePoint plugin for WordPress has a security issue in versions up to 5.0.12. This allows hackers to gain access to the site as any registered user, including administrators, by using a specific user ID. Please note that this can only happen if the “Use WordPress users as customers” option is turned on, which is not the default setting. The issue has been partially fixed in version 5.0.12 and fully fixed in version 5.0.13.

Detected in:

LatePoint Plugin fixed vulnerable versions: >= * <= 5.0.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.