PT-2026-22706 · WordPress · Latepoint – Calendar Booking Plugin For Appointments/Events
Bashu
+2
·
Publicado
2026-03-02
·
Atualizado
2026-03-03
·
CVE-2026-1566
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LatePoint – Calendar Booking Plugin for Appointments and Events versions through 5.2.7
Description
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is susceptible to privilege escalation through a flaw in the password reset functionality. The issue stems from the plugin permitting users with a LatePoint Agent role, while creating new customers, to define the
wordpress user id field. This allows authenticated attackers possessing Agent-level access or higher to obtain elevated privileges by associating a customer with an arbitrary user ID, potentially including administrators, and subsequently resetting the password. The wordpress user id field is used to link a customer to a WordPress user account.Recommendations
Versions prior to 5.2.7 should be updated to address this issue.
Correção
LPE
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Latepoint – Calendar Booking Plugin For Appointments/Events