CVE · Medium

CVE-2026-7652 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7652 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 Weak Password Recovery Mechanism for Forgotten Password Medium 5.3 < 5.5.1 5.5.1 2026-05-08

CVE-2026-7652

The LatePoint plugin for WordPress has a vulnerability in its guest booking flow that allows an attacker to take over a user account. This occurs because the plugin doesn't verify ownership when updating a WordPress user's email address, and an attacker can exploit this by using the guest booking flow to change the email address of a non-admin WordPress user. If the plugin is configured to allow password reset via email and customer authentication is disabled, the attacker can then reset the password for the compromised account to one they control, effectively taking over the account.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.