PT-2026-22706 · WordPress · Latepoint – Calendar Booking Plugin For Appointments/Events

Bashu

+2

·

Published

2026-03-02

·

Updated

2026-03-03

·

CVE-2026-1566

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LatePoint – Calendar Booking Plugin for Appointments and Events versions through 5.2.7
Description The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is susceptible to privilege escalation through a flaw in the password reset functionality. The issue stems from the plugin permitting users with a LatePoint Agent role, while creating new customers, to define the wordpress user id field. This allows authenticated attackers possessing Agent-level access or higher to obtain elevated privileges by associating a customer with an arbitrary user ID, potentially including administrators, and subsequently resetting the password. The wordpress user id field is used to link a customer to a WordPress user account.
Recommendations Versions prior to 5.2.7 should be updated to address this issue.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1566

Affected Products

Latepoint – Calendar Booking Plugin For Appointments/Events