CVE-2026-49083 is a privilege escalation vulnerability affecting LatePoint versions up to and including 5.5.1. The available information indicates that a contributor-level user can escalate privileges within the LatePoint application. Specific details about the vulnerable code path, function, or exploitation mechanism are not currently available from the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single substantive Python exploit script and a minimal README. The main file, CVE-2026-49083.py, is a standalone Python3 tool targeting an alleged authenticated privilege-escalation flaw in the WordPress LatePoint Calendar Booking plugin (claimed vulnerable through 5.5.1). The script is not framework-based. Its structure includes a LatePointPrivEscExploit class for target interaction plus a CLI-driven main() routine that supports single-target mode, mass-scan mode via an input file, multithreading with ThreadPoolExecutor, optional enumeration, and optional result export. Observed capabilities from the visible code include: plugin fingerprinting by probing common WordPress plugin directories, version checking by requesting the plugin main PHP file and parsing a Version header, and orchestration for exploitation and enumeration. The truncated content also shows an enumeration workflow that prints discovered agents and locations, indicating the script can query plugin-related objects before or alongside exploitation. The exploit is intended to abuse customer-to-WordPress user linking logic to elevate privileges from Contributor-level access to Administrator. Fingerprintable target artifacts are primarily WordPress plugin paths under /wp-content/plugins/, especially /wp-content/plugins/latepoint/latepoint.php and readme.txt under several candidate directories. These are used for detection and version validation. No hardcoded victim IPs or external C2 infrastructure are present. The Telegram URL is only branding/output text. Overall, this is an operational web exploit and scanner for WordPress/LatePoint targets, combining detection, vulnerability assessment, enumeration, concurrent scanning, and privilege-escalation attempts.
Repository is a small standalone Python exploit repo with 2 files: a primary script, CVE-2026-49083.py, and a minimal README. The Python script is the clear entry point and implements a CLI exploit tool for CVE-2026-49083, described as an authenticated privilege-escalation flaw in the LatePoint Calendar Booking WordPress plugin affecting versions up to 5.5.1. The script structure centers on a LatePointPrivEscExploit class plus a CLI main() routine. Based on the visible code, the exploit workflow includes: (1) detecting whether the LatePoint plugin is installed by probing common WordPress plugin paths, (2) checking whether the installed version is vulnerable by reading the plugin header from latepoint.php, (3) authenticating to WordPress through /wp-login.php using supplied credentials, (4) optionally enumerating plugin configuration through a LatePointEnumerator helper that retrieves services, agents, and locations, and (5) executing a full exploit path intended to abuse insufficient role validation in customer-to-WordPress user linking logic to elevate privileges to Administrator. Capabilities exposed through CLI flags include --detect for plugin discovery, --check for vulnerability assessment, --enumerate for authenticated reconnaissance, and the default full exploit mode. This makes the repository more than a detector: it is an operational authenticated web exploit with built-in recon and exploitation stages. Fingerprintable targets in the code are WordPress-specific plugin paths under /wp-content/plugins/ and the WordPress login endpoint /wp-login.php. No hardcoded external C2, callback host, or reverse-shell infrastructure is visible in the provided content. The exploit appears to rely entirely on direct HTTP interaction with the target WordPress instance. Overall, this is a focused, standalone authenticated web privilege-escalation exploit for a specific WordPress plugin vulnerability, with moderate operational maturity due to its end-to-end workflow, session handling, version checks, and enumeration support.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.