Account Takeover Vulnerability in LatePoint Plugin for WordPress
CVE-2026-7652

5.3MEDIUM

What is CVE-2026-7652?

The LatePoint plugin for WordPress exposes users to account takeover due to a weak password recovery mechanism within its unauthenticated guest booking flow. This vulnerability arises from the save_connected_wordpress_user() function, which improperly associates a LatePoint customer's email with a linked WordPress user account through wp_update_user() without verifying ownership. Additionally, the guest booking system allows attackers to overwrite an existing customer's email via phone-based integration, lacking authentication checks. Consequently, an unauthenticated attacker can take control of a non-super-admin WordPress user account by triggering the standard WordPress password reset function to an email address they control, provided specific plugin configurations are applied.

Affected Version(s)

LatePoint – Calendar Booking Plugin for Appointments and Events 0 <= 5.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Iden
.