CVE Database /
CVE-2026-8176
CVE · High
CVE-2026-8176 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-8176
|
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2 |
Improper Privilege Management |
High
7.5
|
< 5.5.2
|
5.5.2 |
2026-06-15 |
—
|
CVE-2026-8176
The LatePoint – Calendar Booking Plugin for Appointments and Events has a security flaw in versions up to 5.5.1 that allows certain users to gain administrator-level access. An attacker with agent-level permissions can exploit this vulnerability by manipulating the plugin's functionality, ultimately allowing them to change an administrator's password. This privilege escalation enables attackers to assume control of the WordPress site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings