Description
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 16 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Latepoint
Latepoint latepoint Wordpress Wordpress wordpress |
|
| Vendors & Products |
Latepoint
Latepoint latepoint Wordpress Wordpress wordpress |
Tue, 16 Jun 2026 09:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-16T14:53:59.949Z
Reserved: 2026-05-08T15:11:03.312Z
Link: CVE-2026-8176
Updated: 2026-06-16T14:53:54.788Z
Status : Deferred
Published: 2026-06-16T10:16:28.993
Modified: 2026-06-16T15:22:49.577
Link: CVE-2026-8176
No data.
OpenCVE Enrichment
Updated: 2026-06-16T10:30:15Z
Weaknesses
-
CWE-269
Improper Privilege Management