CVE-2026-11398 | LatePoint Plugin up to 5.6.1 on WordPress Phone Number is_customer_auth_disabled authorization

SecurityVulns

A vulnerability, which was classified as critical, was found in LatePoint Plugin up to 5.6.1 on WordPress. Impacted is the function is_customer_auth_disabled of the component Phone Number Handler. Executing a manipulation can lead to missing authorization.

The identification of this vulnerability is CVE-2026-11398. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More