Executive brief
LatePoint, a popular appointment booking and scheduling plugin for WordPress, contains a security flaw that allows users with low-level 'Contributor' accounts to gain unauthorized administrative privileges. If exploited, an attacker could take full control of the website, potentially leading to data theft, site defacement, or complete service disruption. Business owners should update the plugin immediately to prevent unauthorized access to their web infrastructure.
Technical details
The LatePoint plugin for WordPress (versions <= 5.5.1) is vulnerable to privilege escalation due to incorrect privilege assignment (CWE-266). An attacker with a minimum of 'Contributor' level permissions can exploit this flaw to escalate their privileges to a higher role, potentially gaining full administrative control over the WordPress environment. The attack vector is network-based, though it requires existing low-level authentication and occurs under specific conditions (AC:H). The vulnerability was addressed in version 5.5.2.
Affected products
- LatePoint LatePoint <= 5.5.1
Timeline
- 2026-05-09: other: Reported by researcher VanTastic
- 2026-06-05: advisory: Patchstack published advisory
- 2026-06-15: disclosed: NVD publication date