LatePoint
cpe:2.3:a:latepoint:latepoint:*:*:*:*:wordpress:*:*
- <= 5.2.7
A privilege escalation vulnerability has been identified in the LatePoint Calendar Booking Plugin for WordPress, affecting all versions through 5.2.7. The issue arises because the plugin allows users with the LatePoint Agent role to set the 'wordpress_user_id' field when creating new customers. This functionality can be exploited by authenticated attackers with Agent-level access or higher to link a customer to any user ID, including that of an administrator, and then reset the password, thereby gaining elevated privileges.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling an authenticated user with Agent-level access to gain administrative rights.
Users are advised to update the LatePoint Calendar Booking Plugin for WordPress to version 5.2.8 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.