Executive brief
A vulnerability in the LatePoint booking plugin for WordPress allows users with 'Agent' level access to take over administrator accounts. By exploiting a flaw in how the plugin handles appointment orders, an attacker can modify the email address associated with a site administrator and log in as them. This could lead to a full site takeover, data theft, and complete loss of control over the WordPress website.
Technical details
This vulnerability exists due to an Insecure Direct Object Reference (IDOR) in the create_or_update() function of the OsOrdersController class. An authenticated attacker with 'Agent' privileges can provide an arbitrary customer_id to overwrite the email field of any LatePoint customer, including those linked to WordPress Administrator accounts. Furthermore, OsAuthHelper::authorize_customer() fails to perform role verification when logging in the linked user. By combining these flaws, an attacker can modify an admin's email and subsequently log in with administrative privileges. The issue is addressed in version 5.6.4.
Affected products
- LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events up to, and including, 5.6.3
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory
References
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/orders_controller.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/orders_controller.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/orders_controller.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/auth_helper.php
- https://plugins.trac.wordpress.org/changeset/3590914/latepoint/trunk/lib/controllers/orders_controller.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Flatepoint/tags/5.6.3&new_path=%2Flatepoint/tags/5.6.4
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8f9db3b8-dd37-4d8b-b041-50b453858a39?source=cve