CVE Database /
CVE-2026-6741
CVE · High
CVE-2026-6741 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-6741
|
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2 |
Improper Privilege Management |
High
8.8
|
< 5.4.2
|
5.4.2 |
2026-04-27 |
—
|
CVE-2026-6741
The LatePoint plugin for WordPress contains a security flaw that allows unauthorized access to certain features. Specifically, versions 5.4.1 and earlier lack proper verification of user permissions when linking customer records, enabling attackers with the latepoint_agent role to associate any customer with an administrator's account, ultimately allowing them to reset the admin password and gain full control over the site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings