Junglewise Threat Intelligence

CVE-2026-8176: LatePoint Calendar Booking privilege escalation to Administrator

CVE-2026-8176 · Severity: high · CVSS 7.5 · Published 2026-06-16

Technologies: LatePoint – Calendar Booking Plugin for Appointments and Events. Vendors: LatePoint.

Executive brief

A vulnerability in the LatePoint booking plugin for WordPress allows users with 'Agent' level access to take over administrator accounts. By exploiting a chain of flaws, an attacker can reset an administrator's password and gain full control over the website. This could lead to total site compromise, data theft, or service disruption.

Technical details

The LatePoint plugin for WordPress contains a privilege escalation vulnerability (CWE-269) affecting versions up to 5.5.1. The vulnerability arises from a chain of three independent flaws that allow an authenticated user with 'Agent' privileges or higher to overwrite a WordPress Administrator's password. Notably, this exploit bypasses the need to invoke any Administrator-only APIs. The attack vector is network-based and requires low-level authentication, though the complexity is rated as high. A patch has been released in subsequent versions to address these logic flaws.

Affected products

  • LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events up to, and including, 5.5.1

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References

Related threats