Description
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `default_wp_role_for_customer` setting — a restriction that exists only in the UI dropdown and is never enforced server-side. This makes it possible for authenticated attackers holding a LatePoint role with the `settings__edit` capability (such as an agent or custom role) to overwrite the default WordPress role for new customers with `administrator`, causing any subsequently self-registered LatePoint customer account to be created with full WordPress administrator privileges. Exploitation requires that a WordPress administrator has granted the `settings__edit` capability to a LatePoint agent or custom role, and that a new customer account is registered through LatePoint after the malicious setting change is persisted.
Published: 2026-10-10
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The Appointment Booking Plugin – LatePoint contains an unchecked settings update endpoint. The code iterates over arbitrary settings supplied by a client without a server‑side whitelist, and it applies unsanitised values directly to the default_wp_role_for_customer setting. Because no role validation is enforced, an attacker with the settings__edit capability can change the role assigned to new customers to administrator, thereby granting full WordPress administrative rights to any subsequently self‑registered user.

Affected Systems

All WordPress installations that have the LatePoint booking plugin version 5.7.3 or earlier are affected. The vulnerability is exploitable when an administrator grants the settings__edit capability to a user role such as an agent or custom role. The vendor is LatePoint and the product is the Appointment Booking Plugin – LatePoint, Calendar & Scheduling for WordPress.

Risk and Exploitability

The CVSS score of 8.8 signals a medium‑high severity and the flaw is identified as CWE‑269, an improper authorization error. Exploitation requires an authenticated user with settings__edit capability and a subsequent new customer registration through LatePoint. While the EPSS score is unavailable, the widespread use of LatePoint in WordPress sites means the potential impact is significant. The vulnerability is not listed in the CISA KEV catalog, but it warrants urgent attention due to its high impact and the ease of exploitation for users with editing privileges.

Generated by OpenCVE AI on October 10, 2026 at 06:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the LatePoint plugin to the latest version that removes the unchecked settings update flaw.
  • Revoke the settings__edit capability from all roles that should not modify plugin settings, ensuring only administrators retain that privilege.
  • If an immediate patch is not possible, override the default_wp_role_for_customer setting with a custom hook or snippet to force a lower role such as subscriber for new customers, or temporarily disable self‑registration until the role assignment is corrected.

Generated by OpenCVE AI on October 10, 2026 at 06:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `default_wp_role_for_customer` setting — a restriction that exists only in the UI dropdown and is never enforced server-side. This makes it possible for authenticated attackers holding a LatePoint role with the `settings__edit` capability (such as an agent or custom role) to overwrite the default WordPress role for new customers with `administrator`, causing any subsequently self-registered LatePoint customer account to be created with full WordPress administrator privileges. Exploitation requires that a WordPress administrator has granted the `settings__edit` capability to a LatePoint agent or custom role, and that a new customer account is registered through LatePoint after the malicious setting change is persisted.
Title Appointment Booking Plugin <= 5.7.3 - Authenticated (Custom+) Privilege Escalation to 'settings[default_wp_role_for_customer]' Parameter
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:30:57.307Z

Reserved: 2026-10-02T12:39:39.043Z

Link: CVE-2026-104766

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:40.007

Modified: 2026-10-10T06:16:40.007

Link: CVE-2026-104766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management