Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»SEO & Digital Marketing»WordPress Calendar Plugin Vulnerability Affects Up To 100k Sites
    SEO & Digital Marketing

    WordPress Calendar Plugin Vulnerability Affects Up To 100k Sites

    adminBy adminMarch 4, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    WordPress Calendar Plugin Vulnerability Affects Up To 100k Sites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Wordfence published an advisory on a vulnerability in the LatePoint – Calendar Booking WordPress Plugin that makes it possible for authenticated attackers with Agent-level access and above to gain higher level privileges. The vulnerability received a CVSS vulnerability threat score of 8.8/10. The issue affects all versions up to and including 5.2.7.

    LatePoint WordPress Calendar Plugin

    The LatePoint WordPress plugin is used by service-based businesses to enable customers to book appointments online, manage calendars, accept payments, and send confirmations.

    Authenticated (Agent+) Privilege Escalation

    The vulnerability requires authentication. Attackers must have an account with the LatePoint Agent role or higher. Agent is not an administrator role. It is typically assigned to staff who manage bookings and customer records. On affected sites, that level of access is enough to exploit the flaw.

    The vulnerability is due to the plugin allowing users with a LatePoint Agent role, when creating new customers, to set the wordpress_user_id field. The wordpress_user_id field links a LatePoint customer record to a WordPress user account.

    The plugin does not restrict which WordPress user ID can be assigned. Because of this, an Agent can create a customer and link it to any existing WordPress user account, including an administrator account. After linking the account, the Agent can reset the password.

    According to Wordfence:

    “The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set the ‘wordpress_user_id’ field. This makes it possible for authenticated attackers, with Agent-level access and above, to gain elevated privileges by linking a customer to the arbitrary user ID, including administrators, and then resetting the password.”

    What Attackers Can Do

    This makes it possible for authenticated attackers, with Agent-level access and above, to gain elevated privileges by linking a customer to an arbitrary user ID and then resetting that user’s password.

    Affected Versions And Patch

    The vulnerability affects all versions up to and including 5.2.7. The issue has been patched in version 5.2.8. Users of the LatePoint plugin should update to version 5.2.8 or a newer version.

    Featured Image by Shutterstock/breakermaximus

    100K Affects Calendar Plugin Sites vulnerability WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleYou can now score 50% off the Google Pixel 10 Pro and Pixel 10 Pro Fold
    Next Article EFF to Third Circuit: Electronic Device Searches at the Border Require a Warrant
    admin
    • Website

    Related Posts

    The Complete Guide To Agentic Commerce

    April 19, 2026

    Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

    April 18, 2026

    No-JavaScript fallbacks in 2026: Less critical, still necessary

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Vercel confirms breach as hackers claim to be selling stolen data

    April 19, 2026

    I used a simple Linux command to watch what apps do to my files in real time

    April 19, 2026

    Google TV Home (Android TV) 1.0.900391771 APK Download by Google LLC

    April 19, 2026

    The “most stylish” Galaxy Watch 8 Classic is 31% off at Amazon right now

    April 19, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,401)
    • Privacy & Online Earning (172)
    • SEO & Digital Marketing (850)
    • Tech Tools & Mobile / Apps (1,677)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Vercel confirms breach as hackers claim to be selling stolen data

    April 19, 2026

    I used a simple Linux command to watch what apps do to my files in real time

    April 19, 2026

    Google TV Home (Android TV) 1.0.900391771 APK Download by Google LLC

    April 19, 2026
    Most Popular
    • Vercel confirms breach as hackers claim to be selling stolen data
    • I used a simple Linux command to watch what apps do to my files in real time
    • Google TV Home (Android TV) 1.0.900391771 APK Download by Google LLC
    • The “most stylish” Galaxy Watch 8 Classic is 31% off at Amazon right now
    • Apple AirTag tracking can be misled by replayed Bluetooth signals
    • NIST to stop rating non-priority flaws due to volume increase
    • Home Assistant’s intimidating reputation is completely undeserved once you survive the first week
    • The Complete Guide To Agentic Commerce
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.