Impact
The vulnerability allows a contributor to elevate their privileges within WordPress by exploiting a flaw in the LatePoint plugin version 5.5.1 or earlier. Once the exploit is triggered, the attacker can gain access to higher‑level capabilities normally reserved for administrators. The impact is primarily on the integrity and confidentiality of the site, as elevated permissions could allow the attacker to modify content, user roles, or plugin settings.
Affected Systems
The affected product is the LatePoint WordPress plugin, version 5.5.1 or earlier. This applies to any WordPress installation that has the plugin installed and has contributor‑level users with the ability to interact with the plugin’s interface.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high risk severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated attack via the WordPress administrator dashboard, where a contributor user can trigger the flaw through the plugin’s interface. Successful exploitation results in privileged escalation but does not provide remote code execution or direct denial of service.
OpenCVE Enrichment