← volver
CVE-2025-7038

LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function

CVSS 8.2 HIGHEPSS 0.4%CWE-288
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.2EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
30 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in all versions up to, and including, 5.1.94. The endpoint reads the client-supplied customer email and related customer fields before invoking the internal login handler without verifying login status, capability checks, or a valid AJAX nonce. This makes it possible for unauthenticated attackers to log into any customer’s account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →