CVE · High

CVE-2026-13228 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13228 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4 Improper Privilege Management High 8.8 < 5.6.4 5.6.4 2026-06-30

CVE-2026-13228

The LatePoint plugin for WordPress contains a vulnerability that allows an authenticated user with Agent-level access or higher to elevate their privileges to Administrator. This occurs due to a combination of an insecure direct object reference in the create_or_update function and a missing role verification in the authorization process, which enables an attacker to overwrite an Administrator's email address and subsequently gain Administrator-level access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.