Privilege Escalation in LatePoint Calendar & Scheduling Plugin for WordPress
CVE-2026-104766
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104766?
The LatePoint Calendar & Scheduling plugin for WordPress is susceptible to a Privilege Escalation issue that allows authenticated attackers to manipulate the role assigned to new customers. This vulnerability arises from the absence of a proper allowlist for parameter validation in the OsSettingsController::update() function. When an attacker with the settings__edit capability alters the default_wp_role_for_customer setting, it can lead to newly created LatePoint customer accounts being granted WordPress administrator privileges. The issue is particularly concerning as it requires only that a WordPress administrator has assigned specific capabilities to a LatePoint agent or custom role, facilitating potential exploitation.
Affected Version(s)
Appointment Booking Plugin β LatePoint | Calendar & Scheduling for WordPress 0 <= 5.7.3