Executive brief
The LatePoint plugin for WordPress, which manages appointment and event bookings, contains a security flaw that allows unauthorized individuals to take over user accounts. By exploiting a weakness in how the plugin handles guest bookings and phone-based contact merging, an attacker can change the email address associated with an existing WordPress account. This allows the attacker to reset the account password and gain full access, potentially compromising customer data and site operations.
Technical details
The vulnerability exists in the LatePoint plugin up to version 5.5.0 due to the `save_connected_wordpress_user()` function improperly propagating email updates to linked WordPress accounts via `wp_update_user()` without ownership verification. An unauthenticated attacker can exploit the guest booking flow's phone-based merge feature to overwrite a customer's email address. If WordPress user integration is enabled and customer authentication is disabled, the attacker can change the email of a non-super-admin account and subsequently use the standard WordPress password reset flow to gain full access. Administrator accounts on single-site installs are reportedly not affected.
Affected products
- LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0
Timeline
- 2026-05-09: disclosed
- 2026-05-09: advisory
References
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/latepoint.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/helpers/customer_helper.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/helpers/steps_helper.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.2/lib/helpers/steps_helper.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.5.0/latepoint.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.5.0/lib/helpers/customer_helper.php
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.5.0/lib/helpers/steps_helper.php