Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»SEO & Digital Marketing»WordPress Calendar Plugin Vulnerability Affects Up To 100k Sites
    SEO & Digital Marketing

    WordPress Calendar Plugin Vulnerability Affects Up To 100k Sites

    adminBy adminMarch 4, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    WordPress Calendar Plugin Vulnerability Affects Up To 100k Sites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Wordfence published an advisory on a vulnerability in the LatePoint – Calendar Booking WordPress Plugin that makes it possible for authenticated attackers with Agent-level access and above to gain higher level privileges. The vulnerability received a CVSS vulnerability threat score of 8.8/10. The issue affects all versions up to and including 5.2.7.

    LatePoint WordPress Calendar Plugin

    The LatePoint WordPress plugin is used by service-based businesses to enable customers to book appointments online, manage calendars, accept payments, and send confirmations.

    Authenticated (Agent+) Privilege Escalation

    The vulnerability requires authentication. Attackers must have an account with the LatePoint Agent role or higher. Agent is not an administrator role. It is typically assigned to staff who manage bookings and customer records. On affected sites, that level of access is enough to exploit the flaw.

    The vulnerability is due to the plugin allowing users with a LatePoint Agent role, when creating new customers, to set the wordpress_user_id field. The wordpress_user_id field links a LatePoint customer record to a WordPress user account.

    The plugin does not restrict which WordPress user ID can be assigned. Because of this, an Agent can create a customer and link it to any existing WordPress user account, including an administrator account. After linking the account, the Agent can reset the password.

    According to Wordfence:

    “The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set the ‘wordpress_user_id’ field. This makes it possible for authenticated attackers, with Agent-level access and above, to gain elevated privileges by linking a customer to the arbitrary user ID, including administrators, and then resetting the password.”

    What Attackers Can Do

    This makes it possible for authenticated attackers, with Agent-level access and above, to gain elevated privileges by linking a customer to an arbitrary user ID and then resetting that user’s password.

    Affected Versions And Patch

    The vulnerability affects all versions up to and including 5.2.7. The issue has been patched in version 5.2.8. Users of the LatePoint plugin should update to version 5.2.8 or a newer version.

    Featured Image by Shutterstock/breakermaximus

    100K Affects Calendar Plugin Sites vulnerability WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleYou can now score 50% off the Google Pixel 10 Pro and Pixel 10 Pro Fold
    Next Article EFF to Third Circuit: Electronic Device Searches at the Border Require a Warrant
    admin
    • Website

    Related Posts

    What They Are, and How to Choose the Right One

    March 4, 2026

    Google Zero Is A Lie

    March 4, 2026

    Inside Chrome 146’s agent-ready web preview

    March 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    India APT Sloppy Lemming Targets Defense, Critical Infrastructure

    March 4, 2026

    The MacBook Neo Isn’t the Only Low-Cost Mac Worth Buying

    March 4, 2026

    What They Are, and How to Choose the Right One

    March 4, 2026

    I stopped using Wi-Fi for my TV and I’m never going back

    March 4, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (599)
    • Privacy & Online Earning (90)
    • SEO & Digital Marketing (377)
    • Tech Tools & Mobile / Apps (735)
    • WiFi / Internet & Networking (106)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    India APT Sloppy Lemming Targets Defense, Critical Infrastructure

    March 4, 2026

    The MacBook Neo Isn’t the Only Low-Cost Mac Worth Buying

    March 4, 2026

    What They Are, and How to Choose the Right One

    March 4, 2026
    Most Popular
    • India APT Sloppy Lemming Targets Defense, Critical Infrastructure
    • The MacBook Neo Isn’t the Only Low-Cost Mac Worth Buying
    • What They Are, and How to Choose the Right One
    • I stopped using Wi-Fi for my TV and I’m never going back
    • Digital.ai expands post-build protection for Android and iOS applications
    • How Jamie I.F. is Recovering From a Drop From $100K/Month to $3K/Month
    • Google Zero Is A Lie
    • Phone by Google 210.1.877624726-pixel APK Download by Google LLC
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.