{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/appointment-booking-plugin--latepoint--calendar--scheduling--5.7.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:latepoint:latepoint:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-104766"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Appointment Booking Plugin – LatePoint | Calendar \u0026 Scheduling (\u003c= 5.7.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LatePoint"],"content_html":"\u003cp\u003eThe Appointment Booking Plugin - LatePoint | Calendar \u0026amp; Scheduling for WordPress (versions 5.7.3 and earlier) contains a critical privilege escalation vulnerability. The flaw exists within the \u003ccode\u003eOsSettingsController::update()\u003c/code\u003e function, which fails to properly validate the \u003ccode\u003esettings\u003c/code\u003e parameters provided by a user during an update request. Furthermore, the \u003ccode\u003eOsSettingsHelper::prepare_value()\u003c/code\u003e method does not enforce a whitelist for the \u003ccode\u003edefault_wp_role_for_customer\u003c/code\u003e setting, relying instead solely on client-side UI restrictions that are not validated on the server.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows an authenticated attacker who has been granted the \u003ccode\u003esettings__edit\u003c/code\u003e capability - such as an agent or a user with a custom role - to modify the default registration role to \u003ccode\u003eadministrator\u003c/code\u003e. Consequently, any new user registered through the LatePoint plugin will be assigned full WordPress administrator privileges. This vulnerability is particularly relevant for organizations where delegated administrative permissions are common within the LatePoint platform, as it provides a clear path for lower-privileged users to achieve full site compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains or is assigned a WordPress user role containing the \u003ccode\u003esettings__edit\u003c/code\u003e capability for the LatePoint plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker authenticates to the WordPress administration panel or interacts directly with the plugin's settings update API.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request to the \u003ccode\u003eOsSettingsController::update()\u003c/code\u003e handler.\u003c/li\u003e\n\u003cli\u003eThe attacker injects the \u003ccode\u003edefault_wp_role_for_customer\u003c/code\u003e parameter with the value \u003ccode\u003eadministrator\u003c/code\u003e into the \u003ccode\u003esettings\u003c/code\u003e array of the update request.\u003c/li\u003e\n\u003cli\u003eThe server-side code fails to validate the input against an allowlist, accepting the malicious value.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eOsSettingsHelper::prepare_value()\u003c/code\u003e method persists the new, unauthorized default role configuration to the database.\u003c/li\u003e\n\u003cli\u003eA new customer registers for an account via the LatePoint public-facing booking flow.\u003c/li\u003e\n\u003cli\u003eWordPress creates the new customer account using the attacker-modified default role, granting the new account administrative access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the creation of unauthorized WordPress administrator accounts, leading to full site takeover, data exfiltration, and potential remote code execution on the underlying server. This affects any WordPress site running LatePoint version 5.7.3 or earlier that utilizes delegated role management for plugin settings.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the LatePoint Appointment Booking plugin to a version released after 5.7.3 that incorporates server-side role validation.\u003c/li\u003e\n\u003cli\u003eAudit all existing WordPress user roles and ensure that the \u003ccode\u003esettings__edit\u003c/code\u003e capability is restricted to trusted, verified administrators only.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to monitor for unusual \u003ccode\u003ePOST\u003c/code\u003e requests to WordPress endpoints associated with the LatePoint settings controller that contain parameters referencing \u003ccode\u003edefault_wp_role_for_customer\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRegularly review the \u003ccode\u003ewp_users\u003c/code\u003e and \u003ccode\u003ewp_usermeta\u003c/code\u003e tables for any newly created accounts with the administrator role to identify potential abuse.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T07:50:58Z","date_published":"2026-10-10T07:50:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-latepoint-privesc/","summary":"The LatePoint Appointment Booking plugin for WordPress allows authenticated users with specific capabilities to elevate customer account privileges to administrator via insecure settings management.","title":"Privilege Escalation Vulnerability in LatePoint Appointment Booking Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-latepoint-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Appointment Booking Plugin – LatePoint | Calendar \u0026 Scheduling (\u003c= 5.7.3)","version":"https://jsonfeed.org/version/1.1"}