CVE-2026-7652
The LatePoint plugin for WordPress has a vulnerability in its guest booking flow that allows an attacker to take over a user account. This occurs because the plugin doesn't verify ownership when updating a WordPress user's email address, and an attacker can exploit this by using the guest booking flow to change the email address of a non-admin WordPress user. If the plugin is configured to allow password reset via email and customer authentication is disabled, the attacker can then reset the password for the compromised account to one they control, effectively taking over the account.
Based on public CVE data (MITRE/NVD).