Sceawere
Vulnerability Detail
CVE-2026-104766UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LatePoint Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 2h ago
- Vendor
- latepoint
- Product
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `default_wp_role_for_customer` setting — a restriction that exists only in the UI dropdown and is never enforced server-side. This makes it possible for authenticated attackers holding a LatePoint role with the `settings__edit` capability (such as an agent or custom role) to overwrite the default WordPress role for new customers with `administrator`, causing any subsequently self-registered LatePoint customer account to be created with full WordPress administrator privileges. Exploitation requires that a WordPress administrator has granted the `settings__edit` capability to a LatePoint agent or custom role, and that a new customer account is registered through LatePoint after the malicious setting change is persisted.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-10T06:16:40.007Z",
"pubdate": "2026-10-10T06:16:40.007Z",
"executiveSummary": "The LatePoint WordPress plugin, in versions up to and including 5.7.3, is susceptible to an Insecure Configuration vulnerability leading to Privilege Escalation.\nThe vulnerability originates from a failure to validate user-supplied input during settings updates, specifically concerning the default WordPress user role assigned to new customers.\nAn authenticated user possessing the 'settings__edit' capability can manipulate the application settings to redefine the default registration role as 'administrator'.\nThis flaw allows low-privileged users, such as agents or custom roles assigned specific administrative capabilities, to elevate the privileges of subsequently registered customer accounts to full WordPress administrator status.\nThe risk is critical for multi-user WordPress environments where administrative-level capabilities are delegated to non-administrator roles within the LatePoint plugin ecosystem.\nExploitation requires the attacker to hold an account with the 'settings__edit' capability and necessitates that a new customer registration occurs following the malicious configuration change.",
"technicalDetails": "The vulnerability exists within the 'OsSettingsController::update()' method, which serves as the handler for updating system-wide configurations. The component fails to implement a secure allowlist for input parameters, allowing an attacker to inject arbitrary settings into the plugin configuration storage.\nSpecifically, the 'OsSettingsHelper::prepare_value()' function fails to enforce server-side validation or role allowlisting for the 'default_wp_role_for_customer' parameter. While the plugin's frontend interface restricts this setting via a dropdown menu, the underlying backend logic lacks corresponding server-side enforcement, relying solely on client-side constraints that are easily bypassed by direct HTTP requests.\nThe attack flow proceeds as follows: An authenticated attacker possessing the 'settings__edit' capability sends a crafted POST request to the 'OsSettingsController::update()' endpoint. The payload includes a malicious modification to the 'default_wp_role_for_customer' setting, setting the value to 'administrator'. Because the system does not sanitize or validate this setting against a list of authorized roles, the value is persisted directly into the database.\nOnce the configuration is updated, every subsequent self-registration of a customer through the LatePoint scheduling interface will utilize the modified role. Upon the creation of a new customer, the plugin assigns the 'administrator' role to the user account in the WordPress 'wp_users' table. This results in the new customer account gaining full administrative access to the WordPress environment.\nThe root cause is a Lack of Server-Side Input Validation and Improper Access Control, where internal configuration parameters are implicitly trusted when provided via an authenticated request. The vulnerability is present in versions up to and including 5.7.3. Successful exploitation requires an authenticated session with the 'settings__edit' capability, typically granted to agents or custom roles. The impact of this exploit is a full compromise of the WordPress installation, as an attacker can register an account, obtain administrator privileges, and perform further malicious actions including remote code execution or data exfiltration."
}