PT-2026-49650 · WordPress · Latepoint

·

CVE-2026-8176

·

Published

2026-06-16

·

Updated

2026-06-16

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.5.2
Description The plugin contains a flaw that allows an authenticated user with Agent privileges or higher to elevate their permissions to Administrator. This is achieved by chaining three independent issues, including an Insecure Direct Object Reference (IDOR)—a vulnerability where an application provides direct access to objects based on user-supplied input—within the create or update function of the OsOrdersController and an unauthenticated password reset mechanism in the Customer-Cabinet. This chain enables the attacker to overwrite a WordPress Administrator's password without accessing Administrator-only APIs.
Recommendations Update the plugin to a version later than 5.5.1.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8176

Affected Products

Latepoint