CVE · High

CVE-2026-6741 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6741 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2 Improper Privilege Management High 8.8 < 5.4.2 5.4.2 2026-04-27

CVE-2026-6741

The LatePoint plugin for WordPress contains a security flaw that allows unauthorized access to certain features. Specifically, versions 5.4.1 and earlier lack proper verification of user permissions when linking customer records, enabling attackers with the latepoint_agent role to associate any customer with an administrator's account, ultimately allowing them to reset the admin password and gain full control over the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.