CVE-2026-1566
8.8LatePoint · Calendar Booking Plugin for Appointments and Events
The LatePoint Calendar Booking plugin for WordPress is susceptible to privilege escalation due to insufficient validation when linking customer accounts to existing WordPress user IDs.
Executive summary
The LatePoint calendar booking plugin contains a privilege escalation vulnerability that allows authenticated attackers to gain administrative access.
Vulnerability
This flaw involves improper privilege management (CWE-269) where users with an Agent role can assign arbitrary WordPress user IDs to new customers. By linking a customer account to an administrator ID, an attacker can trigger a password reset to achieve full administrative control.
Business impact
Successful exploitation allows an authenticated attacker to escalate privileges to the administrator level, resulting in complete compromise of the WordPress site. Given the CVSS score of 8.8, this vulnerability presents a high risk of unauthorized data access, malicious code injection, and total loss of system integrity.
Remediation
Immediate Action: Update the LatePoint plugin to the latest version, ensuring all instances are patched beyond version 5.2.7.
Proactive Monitoring: Review WordPress user account logs for suspicious activity or unauthorized password reset requests initiated by users with the Agent role.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block suspicious requests targeting plugin-specific customer creation endpoints while the update is being deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this privilege escalation flaw necessitates immediate attention from administrators managing sites that utilize the LatePoint plugin. Organizations should prioritize updating to the latest secure version to prevent potential administrative account takeover and subsequent site compromise.
More LatePoint CVEs
Sources
Originally found and disclosed by Hung Nguyen, per the CVE Program record.