CVE-2026-7652Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due to the save_connected_wordpress_user() function propagating a LatePoint customer's email address to its linked WordPress user account via wp_update_user() without any ownership verification, combined with the guest booking flow's ability to overwrite an existing customer's email through phone-based merge without authentication. This makes it possible for unauthenticated attackers to overwrite the email address of a non-super-admin WordPress user account that is not yet linked to a LatePoint customer, enabling full account takeover by subsequently triggering the standard WordPress password-reset flow to the attacker-controlled address granted the plugin is configured with WordPress user integration enabled, phone-based contact merging, and customer authentication disabled. Administrator accounts on single-site installs are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-11: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-11: 105-0905-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure1General1
2026-05-111
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7652 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7652 #CVE-2026-7652 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/qkBcu82nmR

    Post summary

    The tweet announces the disclosure of CVE-2026-7652, noting its medium severity and that it targets WordPress, but offers no details on exploitation, tools, or remediation.

    0000037
    157 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7652 The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, a… https://www.cve.org/CVERecord?id=CVE-2026-7652

    Post summary

    The CVE-2026-7652 reveals an account takeover flaw in the LatePoint WordPress plugin caused by weak password recovery, but the snippet provides no PoC, exploit, patch, or evidence of active use.

    0000091
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7652 Account Takeover in LatePoint WordPress Plugin via Weak Password Recovery Mechanism https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7652

    Post summary

    The entry identifies CVE-2026-7652 as an account takeover flaw in LatePoint, noting weak password recovery mechanisms, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    0000054
    4.0K followersView on X

Explore more