PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104766 latepoint CVE debrief

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin is vulnerable to Privilege Escalation in versions up to and including 5.7.3. Authenticated attackers with the `settings__edit` capability can overwrite the default WordPress role for new customers with `administrator`, allowing self-registered LatePoint customer accounts to be created with full WordPress administrator privileges.

Vendor
latepoint
Product
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress should assess exposure and prioritize remediation, especially if the `settings__edit` capability is granted to non-administrator roles.

Why it matters

CVE-2026-104766 allows authenticated attackers to escalate privileges by overwriting the default WordPress role for new customers with `administrator`, impacting WordPress installations with the Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress.

  • Potential privilege escalation to administrator role for self-registered customer accounts.
  • Possible unauthorized access to sensitive WordPress functionality.
  • Required verification of customer account roles and settings.
  • Necessity to restrict the `settings__edit` capability to trusted roles.

Technical summary

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin is vulnerable to Privilege Escalation due to improper validation of the `settings` parameters in the `OsSettingsController::update()` handler and `OsSettingsHelper::prepare_value()`. This allows authenticated attackers with the `settings__edit` capability to overwrite the default WordPress role for new customers with `administrator`, potentially leading to unauthorized access to sensitive WordPress functionality. Defenders should prioritize verifying and remediating this vulnerability, especially in environments where the `settings__edit` capability is granted to non-administrator roles. The vulnerability exists due to the `

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially in environments where the `settings__edit` capability is granted to non-administrator roles.

Recommended defensive actions

  • Verify the version of the Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress and upgrade to a patched version if necessary.
  • Review and restrict the `settings__edit` capability to only trusted roles.
  • Monitor for new customer account registrations and verify their roles.
  • Implement additional logging and monitoring to detect potential exploitation attempts.
  • Conduct a thorough review of existing customer accounts to identify potential unauthorized access.
  • Update incident response plans to include procedures for addressing potential privilege escalation attacks.
  • Perform a comprehensive asset inventory to identify all systems that may be affected by this vulnerability.

Evidence notes

The vulnerability exists due to the `OsSettingsController::update()` handler and `OsSettingsHelper::prepare_value()` not enforcing role allowlist validation for the `default_wp_role_for_customer` setting. This allows attackers with the `settings__edit` capability to escalate privileges.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104766 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104766

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104766 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104766

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Appointment Booking Plugin <= 5.7.3 - Authenticated (Custom+) Privilege Escalation to 'settings[

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104766.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.7.3/lib/controllers/settings_controller.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.7.3/lib/helpers/settings_helper.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/latepoint/tags/5.7.3/lib/helpers/customer_helper.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.