
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1566 is a privilege escalation vulnerability via password reset in the LatePoint – Calendar Booking Plugin for Appointments and Events for WordPress, affecting all versions up to and including 5.2.7. The flaw allows authenticated attackers with Agent-level access to link a customer account to an arbitrary WordPress user ID (including administrators) and then reset that administrator's password, effectively gaining full administrative control. It was published on March 3, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, ENISA EUVD).
The root cause is improper privilege management (CWE-269): when a LatePoint Agent creates a new customer, the plugin fails to restrict or validate the wordpress_user_id field, allowing the agent to associate the new customer record with any existing WordPress user ID, including site administrators. An attacker exploits this by submitting a crafted customer-creation request with a target administrator's wordpress_user_id, then triggering the plugin's password reset flow for that customer — which resets the linked administrator's WordPress account password. The attack requires only network access and a valid Agent-level account; no user interaction from the victim is needed (Wordfence, infinitsec).
Successful exploitation grants an attacker full administrative access to the WordPress installation, enabling unauthorized content modification, malware injection, data theft, creation of backdoor accounts, and complete site takeover. All three security pillars are affected — confidentiality (access to all site data and credentials), integrity (ability to modify any content or settings), and availability (potential to disable or destroy the site). Any WordPress site running LatePoint ≤ 5.2.7 with at least one Agent-role user is at risk (Wordfence, ENISA EUVD).
/wp-json/wp/v2/users).wordpress_user_id field to the target administrator's user ID.wordpress_user_id references a high-privilege WordPress user (e.g., administrator); review wp_latepoint_customers for anomalous user ID associations.wp_users or wp_usermeta tables reflecting password hash updates for admin accounts./wp-admin/admin-ajax.php with LatePoint-specific action parameters) containing a wordpress_user_id parameter set to a known admin user ID, originating from Agent-role sessions.The primary remediation is to update the LatePoint – Calendar Booking Plugin to a version newer than 5.2.7 once a patched release is available; the fix was committed in the WordPress plugin repository (changeset 3463945) (WordPress SVN). Until patching is possible, restrict the LatePoint Agent role exclusively to fully trusted users and audit existing Agent accounts. Consider temporarily disabling the plugin if it is not actively required. Implement WordPress activity logging (e.g., via a security plugin) to monitor for suspicious customer creation events or unexpected administrator password resets (Wordfence, Sucuri Blog).
Wordfence, which discovered and assigned the CVE, published the vulnerability in their weekly WordPress vulnerability report for the week of March 2–8, 2026, highlighting it as a notable privilege escalation risk (Wordfence Blog). Sucuri included it in their March 2026 vulnerability patch roundup, recommending prompt updates (Sucuri Blog). The vulnerability received standard automated coverage across security aggregators (VulDB, Vulners, RedPacket Security) and social platforms (Bluesky, Mastodon), with no exceptional community controversy or debate noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."