PT-2026-49650 · WordPress · Latepoint
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.5.2
Description
The plugin contains a flaw that allows an authenticated user with Agent privileges or higher to elevate their permissions to Administrator. This is achieved by chaining three independent issues, including an Insecure Direct Object Reference (IDOR)—a vulnerability where an application provides direct access to objects based on user-supplied input—within the
create or update function of the OsOrdersController and an unauthenticated password reset mechanism in the Customer-Cabinet. This chain enables the attacker to overwrite a WordPress Administrator's password without accessing Administrator-only APIs.Recommendations
Update the plugin to a version later than 5.5.1.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint