Impact
The Appointment Booking Plugin – LatePoint contains an unchecked settings update endpoint. The code iterates over arbitrary settings supplied by a client without a server‑side whitelist, and it applies unsanitised values directly to the default_wp_role_for_customer setting. Because no role validation is enforced, an attacker with the settings__edit capability can change the role assigned to new customers to administrator, thereby granting full WordPress administrative rights to any subsequently self‑registered user.
Affected Systems
All WordPress installations that have the LatePoint booking plugin version 5.7.3 or earlier are affected. The vulnerability is exploitable when an administrator grants the settings__edit capability to a user role such as an agent or custom role. The vendor is LatePoint and the product is the Appointment Booking Plugin – LatePoint, Calendar & Scheduling for WordPress.
Risk and Exploitability
The CVSS score of 8.8 signals a medium‑high severity and the flaw is identified as CWE‑269, an improper authorization error. Exploitation requires an authenticated user with settings__edit capability and a subsequent new customer registration through LatePoint. While the EPSS score is unavailable, the widespread use of LatePoint in WordPress sites means the potential impact is significant. The vulnerability is not listed in the CISA KEV catalog, but it warrants urgent attention due to its high impact and the ease of exploitation for users with editing privileges.
OpenCVE Enrichment