<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:latepoint:latepoint:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alatepointlatepointwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:50:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alatepointlatepointwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation Vulnerability in LatePoint Appointment Booking Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-latepoint-privesc/</link><pubDate>Sat, 10 Oct 2026 07:50:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-latepoint-privesc/</guid><description>The LatePoint Appointment Booking plugin for WordPress allows authenticated users with specific capabilities to elevate customer account privileges to administrator via insecure settings management.</description><content:encoded><![CDATA[<p>The Appointment Booking Plugin - LatePoint | Calendar &amp; Scheduling for WordPress (versions 5.7.3 and earlier) contains a critical privilege escalation vulnerability. The flaw exists within the <code>OsSettingsController::update()</code> function, which fails to properly validate the <code>settings</code> parameters provided by a user during an update request. Furthermore, the <code>OsSettingsHelper::prepare_value()</code> method does not enforce a whitelist for the <code>default_wp_role_for_customer</code> setting, relying instead solely on client-side UI restrictions that are not validated on the server.</p>
<p>This vulnerability allows an authenticated attacker who has been granted the <code>settings__edit</code> capability - such as an agent or a user with a custom role - to modify the default registration role to <code>administrator</code>. Consequently, any new user registered through the LatePoint plugin will be assigned full WordPress administrator privileges. This vulnerability is particularly relevant for organizations where delegated administrative permissions are common within the LatePoint platform, as it provides a clear path for lower-privileged users to achieve full site compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker obtains or is assigned a WordPress user role containing the <code>settings__edit</code> capability for the LatePoint plugin.</li>
<li>The attacker authenticates to the WordPress administration panel or interacts directly with the plugin's settings update API.</li>
<li>The attacker crafts a request to the <code>OsSettingsController::update()</code> handler.</li>
<li>The attacker injects the <code>default_wp_role_for_customer</code> parameter with the value <code>administrator</code> into the <code>settings</code> array of the update request.</li>
<li>The server-side code fails to validate the input against an allowlist, accepting the malicious value.</li>
<li>The <code>OsSettingsHelper::prepare_value()</code> method persists the new, unauthorized default role configuration to the database.</li>
<li>A new customer registers for an account via the LatePoint public-facing booking flow.</li>
<li>WordPress creates the new customer account using the attacker-modified default role, granting the new account administrative access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the creation of unauthorized WordPress administrator accounts, leading to full site takeover, data exfiltration, and potential remote code execution on the underlying server. This affects any WordPress site running LatePoint version 5.7.3 or earlier that utilizes delegated role management for plugin settings.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update the LatePoint Appointment Booking plugin to a version released after 5.7.3 that incorporates server-side role validation.</li>
<li>Audit all existing WordPress user roles and ensure that the <code>settings__edit</code> capability is restricted to trusted, verified administrators only.</li>
<li>Implement WAF rules to monitor for unusual <code>POST</code> requests to WordPress endpoints associated with the LatePoint settings controller that contain parameters referencing <code>default_wp_role_for_customer</code>.</li>
<li>Regularly review the <code>wp_users</code> and <code>wp_usermeta</code> tables for any newly created accounts with the administrator role to identify potential abuse.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>