CVE-2026-104766
Received Received - Intake

Privilege Escalation in LatePoint WordPress Plugin

Vulnerability report for CVE-2026-104766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `default_wp_role_for_customer` setting β€” a restriction that exists only in the UI dropdown and is never enforced server-side. This makes it possible for authenticated attackers holding a LatePoint role with the `settings__edit` capability (such as an agent or custom role) to overwrite the default WordPress role for new customers with `administrator`, causing any subsequently self-registered LatePoint customer account to be created with full WordPress administrator privileges. Exploitation requires that a WordPress administrator has granted the `settings__edit` capability to a LatePoint agent or custom role, and that a new customer account is registered through LatePoint after the malicious setting change is persisted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privilege escalation vulnerability in the Appointment Booking Plugin – LatePoint for WordPress. It allows authenticated attackers with certain roles to change the default WordPress role for new customers to administrator by exploiting improper handling of settings parameters. The issue occurs because the plugin does not validate or restrict which settings can be modified server-side, enabling attackers to set the default role to administrator without proper authorization.

Detection Guidance

Check WordPress plugin versions for LatePoint up to 5.7.3. Review user roles with settings__edit capability. Inspect default_wp_role_for_customer settings for unauthorized changes to administrator role.

Impact Analysis

If you use this plugin, an attacker with a LatePoint role that has the settings__edit capability could escalate their privileges to WordPress administrator. This means they could take full control of your WordPress site, install malicious plugins, steal data, or disrupt operations. The impact depends on whether an administrator has granted the settings__edit capability to untrusted roles.

Compliance Impact

This vulnerability could lead to unauthorized access and control of a WordPress site, which may result in data breaches. For GDPR, this could mean unauthorized access to personal data, leading to potential fines. For HIPAA, it could expose protected health information, violating compliance requirements. Organizations must address this to maintain data protection and regulatory compliance.

Mitigation Strategies

Update the Appointment Booking Plugin – LatePoint to the latest version beyond 5.7.3. Remove the settings__edit capability from any LatePoint agent or custom role that does not require full WordPress administrator privileges. Monitor for unauthorized changes to the default_wp_role_for_customer setting.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart