WordPress Plugin Vulnerabilities
LatePoint < 5.5.2 - Agent+ Privilege Escalation to Administrator
Description
The plugin does not properly prevent privilege escalation, allowing authenticated attackers with Agent-level access and above to overwrite a WordPress Administrator's password and thereby elevate their privileges to Administrator.
Affects Plugins
References
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
d.v4n_s3c
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-06-15 (about 2 months ago)
Added
2026-06-16 (about 2 months ago)
Last Updated
2026-06-16 (about 2 months ago)