S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Feb 3, 2026

CVE-2024-8911 Scanner

CVE-2024-8911 Scanner - SQL Injection vulnerability in LatePoint

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8911
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note that changing a WordPress user's password is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. Without this setting enabled, only the passwords of plugin customers, which are stored and managed in a separate database table, can be modified.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LatePoint Pluginby latepoint
0
latepointby latepoint
0
Updated Aug 22, 2026View on NVD →
Detail

LatePoint is a WordPress plugin designed to streamline appointment bookings. Widely utilized by businesses like salons, clinics, and educational institutions, it helps manage customer appointments efficiently. The software integrates seamlessly with WordPress websites, providing a user-friendly interface for booking management. Additionally, it offers customizable widgets and notification systems, catering to the needs of businesses seeking to enhance customer engagement. Its flexibility and scalability make it ideal for small to medium enterprises. However, like many online platforms, LatePoint requires robust security measures to safeguard sensitive information.

The SQL Injection vulnerability in LatePoint allows attackers to manipulate SQL queries through unescaped parameters. This flaw exists due to insufficient input validation and preparation of SQL queries. Exploiting this vulnerability can lead to unauthorized database access, allowing attackers to alter data. It particularly affects the 'Use WordPress users as customers' setting, although this is disabled by default. The severity of this issue is critical, potentially leading to account compromise. Immediate attention to patching is recommended for affected versions to prevent data breaches.

Technically, the vulnerability lies in the way parameters are passed in SQL queries in the LatePoint plugin. The endpoint 'wp-admin/admin-ajax.php' is vulnerable when making POST requests with insufficiently sanitized inputs. Attackers can inject malicious SQL code, leading to altered database queries. The vulnerability can be exploited by sending crafted requests to modify user passwords. This affects configurations where WordPress users are set as customers, although plugin-specific users can also be at risk. Ensuring proper escaping and validation of parameters can mitigate this issue.

Exploitation of this vulnerability can result in unauthorized password changes and potential account takeovers. Malicious actors may gain administrator access, leading to full control over WordPress sites using LatePoint. Data breaches could occur, exposing sensitive user information stored in the database. Businesses relying on LatePoint may face operational disruptions and damage to reputation. Furthermore, legislative penalties might be incurred due to non-compliance with data protection regulations. Addressing this vulnerability is critical to prevent such adverse outcomes.

REFERENCES

Solution Advice
  • Apply the latest security patches issued by the plugin's developers.
  • Disable the "Use WordPress users as customers" setting if not necessary.
  • Utilize input sanitization techniques to prevent injection attacks.
  • Conduct regular security audits on WordPress installations.
  • Implement a web application firewall to block malicious requests.
  • Review and limit the use of admin privileges across the platform.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-8911 Scanner - SQL Injection vulnerability in LatePoint S4E