WP Security CheckVulnerability data as of October 10, 2026

Vulnerability alerts / October 9, 2026

Vulnerability in Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — CVE-2026-104766

HighSeverity
CVSS 8.8
—Estimated exploit probability
EPSS
100,000+ sitesInstalls
5.7.4Fixed in

What to do now

Update Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress to 5.7.4 or later.

Affected versions

  • Everything up to and including 5.7.3

Affected: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (plugin, latepoint)

Check: The plugin on wordpress.org / Our record for Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress

What the vulnerability is

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `default_wp_role_for_customer` setting — a restriction that exists only in the UI dropdown and is never enforced server-side. This makes it possible for authenticated attackers holding a LatePoint role with the `settings__edit` capability (such as an agent or custom role) to overwrite the default WordPress role for new customers with `administrator`, causing any subsequently self-registered LatePoint customer account to be created with full WordPress administrator privileges. Exploitation requires that a WordPress administrator has granted the `settings__edit` capability to a LatePoint agent or custom role, and that a new customer account is registered through LatePoint after the malicious setting change is persisted.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/38870e14-2e8f-4281-adb6-4be3b1d3d2ce
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts