PatchSiren cyber security CVE debrief
CVE-2026-104766 latepoint CVE debrief
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin is vulnerable to Privilege Escalation in versions up to and including 5.7.3. Authenticated attackers with the `settings__edit` capability can overwrite the default WordPress role for new customers with `administrator`, allowing self-registered LatePoint customer accounts to be created with full WordPress administrator privileges.
- Vendor
- latepoint
- Product
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress should assess exposure and prioritize remediation, especially if the `settings__edit` capability is granted to non-administrator roles.
Why it matters
CVE-2026-104766 allows authenticated attackers to escalate privileges by overwriting the default WordPress role for new customers with `administrator`, impacting WordPress installations with the Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress.
- Potential privilege escalation to administrator role for self-registered customer accounts.
- Possible unauthorized access to sensitive WordPress functionality.
- Required verification of customer account roles and settings.
- Necessity to restrict the `settings__edit` capability to trusted roles.
Technical summary
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin is vulnerable to Privilege Escalation due to improper validation of the `settings` parameters in the `OsSettingsController::update()` handler and `OsSettingsHelper::prepare_value()`. This allows authenticated attackers with the `settings__edit` capability to overwrite the default WordPress role for new customers with `administrator`, potentially leading to unauthorized access to sensitive WordPress functionality. Defenders should prioritize verifying and remediating this vulnerability, especially in environments where the `settings__edit` capability is granted to non-administrator roles. The vulnerability exists due to the `
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in environments where the `settings__edit` capability is granted to non-administrator roles.
Recommended defensive actions
- Verify the version of the Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress and upgrade to a patched version if necessary.
- Review and restrict the `settings__edit` capability to only trusted roles.
- Monitor for new customer account registrations and verify their roles.
- Implement additional logging and monitoring to detect potential exploitation attempts.
- Conduct a thorough review of existing customer accounts to identify potential unauthorized access.
- Update incident response plans to include procedures for addressing potential privilege escalation attacks.
- Perform a comprehensive asset inventory to identify all systems that may be affected by this vulnerability.
Evidence notes
The vulnerability exists due to the `OsSettingsController::update()` handler and `OsSettingsHelper::prepare_value()` not enforcing role allowlist validation for the `default_wp_role_for_customer` setting. This allows attackers with the `settings__edit` capability to escalate privileges.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104766 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104766
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104766 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104766
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Appointment Booking Plugin <= 5.7.3 - Authenticated (Custom+) Privilege Escalation to 'settings[
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104766.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.7.3/lib/controllers/settings_controller.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.7.3/lib/helpers/settings_helper.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.7.3/lib/helpers/customer_helper.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.