Account Takeover Vulnerability in LatePoint Plugin for WordPress
CVE-2026-7652
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 May 2026
What is CVE-2026-7652?
The LatePoint plugin for WordPress exposes users to account takeover due to a weak password recovery mechanism within its unauthenticated guest booking flow. This vulnerability arises from the save_connected_wordpress_user() function, which improperly associates a LatePoint customer's email with a linked WordPress user account through wp_update_user() without verifying ownership. Additionally, the guest booking system allows attackers to overwrite an existing customer's email via phone-based integration, lacking authentication checks. Consequently, an unauthenticated attacker can take control of a non-super-admin WordPress user account by triggering the standard WordPress password reset function to an email address they control, provided specific plugin configurations are applied.
Affected Version(s)
LatePoint β Calendar Booking Plugin for Appointments and Events 0 <= 5.5.0