CVE detail
CVE-2026-6741
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires the customer__edit capability granted to the latepoint_agent role by default, without verifying whether the target WordPress user ID belongs to a privileged account. This makes it possible for authenticated attackers with the latepoint_agent role to link any LatePoint customer record to an administrator's WordPress account and subsequently reset the administrator's password via the normal customer password-reset flow, resulting in full site takeover.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/71e99412-031e-4f4a-9126-dd3a37975246?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comApr 27, 2026, 8:16 PM - https://wordpress.org/plugins/latepoint/wordpress.org
No excerpt available.
Release Noteswordpress.orgApr 27, 2026, 8:16 PM - https://plugins.trac.wordpress.org/changeset/3514330/latepointplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgApr 27, 2026, 8:16 PM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.1/lib/models/customer_model.phpplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgApr 27, 2026, 8:16 PM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.1/lib/helpers/roles_helper.phpplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgApr 27, 2026, 8:16 PM - https://plugins.trac.wordpress.org/browser/latepoint/tags/5.4.1/lib/abilities/customers/connect-customer-to-wp-user.phpplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgApr 27, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-12502CVSS 8.4 · High
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `supera…
- CVE-2026-16743CVSS 5.5 · Medium
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the…
- CVE-2026-10610CVSS 8.5 · High
Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.
- CVE-2026-7483CVSS 8.5 · High
Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.
- CVE-2026-12981CVSS 7.5 · High
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the passw…
- CVE-2026-12497CVSS 7.5 · High
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role…