CVE-2026-1566
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1566 is a privilege escalation vulnerability via password reset in the LatePoint – Calendar Booking Plugin for Appointments and Events for WordPress, affecting all versions up to and including 5.2.7. The flaw allows authenticated attackers with Agent-level access to link a customer account to an arbitrary WordPress user ID (including administrators) and then reset that administrator's password, effectively gaining full administrative control. It was published on March 3, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, ENISA EUVD).

Technical details

The root cause is improper privilege management (CWE-269): when a LatePoint Agent creates a new customer, the plugin fails to restrict or validate the wordpress_user_id field, allowing the agent to associate the new customer record with any existing WordPress user ID, including site administrators. An attacker exploits this by submitting a crafted customer-creation request with a target administrator's wordpress_user_id, then triggering the plugin's password reset flow for that customer — which resets the linked administrator's WordPress account password. The attack requires only network access and a valid Agent-level account; no user interaction from the victim is needed (Wordfence, infinitsec).

Impact

Successful exploitation grants an attacker full administrative access to the WordPress installation, enabling unauthorized content modification, malware injection, data theft, creation of backdoor accounts, and complete site takeover. All three security pillars are affected — confidentiality (access to all site data and credentials), integrity (ability to modify any content or settings), and availability (potential to disable or destroy the site). Any WordPress site running LatePoint ≤ 5.2.7 with at least one Agent-role user is at risk (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the LatePoint plugin (version ≤ 5.2.7) by inspecting page source, plugin-specific URLs, or using tools like WPScan. Enumerate the target administrator's WordPress user ID (often user ID 1 for the first admin, or discoverable via the WordPress REST API at /wp-json/wp/v2/users).
  2. Obtain Agent credentials: Acquire a LatePoint Agent-level account through registration, social engineering, or credential compromise — the minimum privilege required for exploitation.
  3. Create a malicious customer record: While authenticated as an Agent, submit a customer creation request (e.g., via the LatePoint admin panel or a crafted POST request to the relevant endpoint) and set the wordpress_user_id field to the target administrator's user ID.
  4. Trigger password reset: Use the LatePoint plugin's password reset functionality for the newly created customer account. Because the customer is now linked to the administrator's WordPress user ID, the reset will change the administrator's WordPress account password.
  5. Gain administrative access: Log in to WordPress using the administrator's username and the newly reset password, achieving full site administrative control (Wordfence, infinitsec).

Indicators of compromise

  • Logs: WordPress authentication logs showing an administrator account logging in from an unfamiliar IP address or at an unusual time shortly after a LatePoint customer creation event; password reset log entries for administrator accounts not initiated by the administrator themselves.
  • Database: Unexpected entries in the LatePoint customers table where wordpress_user_id references a high-privilege WordPress user (e.g., administrator); review wp_latepoint_customers for anomalous user ID associations.
  • WordPress Activity: New administrator-level sessions or actions (plugin installs, user creation, settings changes) not attributable to known admins; unexpected changes to wp_users or wp_usermeta tables reflecting password hash updates for admin accounts.
  • Network: POST requests to LatePoint customer creation endpoints (e.g., /wp-admin/admin-ajax.php with LatePoint-specific action parameters) containing a wordpress_user_id parameter set to a known admin user ID, originating from Agent-role sessions.

Mitigation and workarounds

The primary remediation is to update the LatePoint – Calendar Booking Plugin to a version newer than 5.2.7 once a patched release is available; the fix was committed in the WordPress plugin repository (changeset 3463945) (WordPress SVN). Until patching is possible, restrict the LatePoint Agent role exclusively to fully trusted users and audit existing Agent accounts. Consider temporarily disabling the plugin if it is not actively required. Implement WordPress activity logging (e.g., via a security plugin) to monitor for suspicious customer creation events or unexpected administrator password resets (Wordfence, Sucuri Blog).

Community reactions

Wordfence, which discovered and assigned the CVE, published the vulnerability in their weekly WordPress vulnerability report for the week of March 2–8, 2026, highlighting it as a notable privilege escalation risk (Wordfence Blog). Sucuri included it in their March 2026 vulnerability patch roundup, recommending prompt updates (Sucuri Blog). The vulnerability received standard automated coverage across security aggregators (VulDB, Vulners, RedPacket Security) and social platforms (Bluesky, Mastodon), with no exceptional community controversy or debate noted.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65562MEDIUM6.5
  • betterdocs
NoYesJul 27, 2026
CVE-2026-65563MEDIUM5.9
  • themeisle-companion
NoYesJul 27, 2026
CVE-2026-65557MEDIUM5.9
  • woocommerce-abandoned-cart
NoYesJul 27, 2026
CVE-2026-65567MEDIUM5.3
  • event-tickets
NoYesJul 27, 2026
CVE-2026-65568MEDIUM5
  • visualcomposer
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management