WordPress Plugin Vulnerabilities

LatePoint < 5.5.2 - Agent+ Privilege Escalation to Administrator

Description

The plugin does not properly prevent privilege escalation, allowing authenticated attackers with Agent-level access and above to overwrite a WordPress Administrator's password and thereby elevate their privileges to Administrator.

Affects Plugins

Fixed in 5.5.2

References

Classification

Miscellaneous

Original Researcher
d.v4n_s3c
Verified
No

Timeline

Publicly Published
2026-06-15 (about 2 months ago)
Added
2026-06-16 (about 2 months ago)
Last Updated
2026-06-16 (about 2 months ago)

Other