Junglewise Threat Intelligence

CVE-2026-49083: LatePoint WordPress plugin privilege escalation in Contributor accounts

CVE-2026-49083 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: LatePoint. Vendors: LatePoint.

Executive brief

LatePoint, a popular appointment booking and scheduling plugin for WordPress, contains a security flaw that allows users with low-level 'Contributor' accounts to gain unauthorized administrative privileges. If exploited, an attacker could take full control of the website, potentially leading to data theft, site defacement, or complete service disruption. Business owners should update the plugin immediately to prevent unauthorized access to their web infrastructure.

Technical details

The LatePoint plugin for WordPress (versions <= 5.5.1) is vulnerable to privilege escalation due to incorrect privilege assignment (CWE-266). An attacker with a minimum of 'Contributor' level permissions can exploit this flaw to escalate their privileges to a higher role, potentially gaining full administrative control over the WordPress environment. The attack vector is network-based, though it requires existing low-level authentication and occurs under specific conditions (AC:H). The vulnerability was addressed in version 5.5.2.

Affected products

  • LatePoint LatePoint <= 5.5.1

Timeline

  • 2026-05-09: other: Reported by researcher VanTastic
  • 2026-06-05: advisory: Patchstack published advisory
  • 2026-06-15: disclosed: NVD publication date

References

Related threats