CVE-2026-6741 is a privilege-escalation vulnerability in the LatePoint – Calendar Booking Plugin for Appointments and Events for WordPress. It affects versions up to and including 5.4.1 and is tied to the WordPress Abilities API path used by the plugin. The flaw is caused by a missing authorization check in the execute() method of lib/abilities/customers/connect-customer-to-wp-user.php. The vulnerable logic requires only the customer__edit capability, which is granted to the latepoint_agent role by default, and verifies only that the supplied target WordPress user exists via get_userdata(). It does not validate whether the target wp_user_id belongs to a privileged WordPress account. As a result, an authenticated attacker with the latepoint_agent role can associate a LatePoint customer record with an arbitrary WordPress user account, including an administrator account. The attacker can then abuse the normal LatePoint customer password-reset workflow: the customer record remains under attacker control for reset-token delivery, while the linked wordpress_user_id causes the password update path to call wp_set_password() for the targeted administrator account. This results in administrative account takeover and full compromise of the WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit repo containing one Python exploit script and one README. The main file, CVE-2026-6741.py, is an operational exploit for CVE-2026-6741 affecting the LatePoint WordPress booking plugin <= 5.4.1. It targets an authenticated privilege-escalation flaw where a user with the latepoint_agent role can invoke a vulnerable Abilities API action to connect a LatePoint customer record to an arbitrary WordPress user account, including an administrator. The exploit then abuses the plugin's password reset/change flow so that updating the linked customer's password calls wp_set_password() on the administrator account, resulting in administrator takeover. Observed code structure indicates a full attack workflow rather than simple detection. The script includes helper routines for synchronized output/progress display, agent_login() for WordPress authentication, get_rest_nonce() for obtaining the REST nonce from admin-ajax or wp-admin page content, and get_current_user() for validating the authenticated session. The truncated content and README make clear the remaining logic performs target admin ID discovery, customer linking, password reset initiation, token handling, password change, and optional bulk targeting with ThreadPoolExecutor. The CLI supports both single-target and list-based scanning/exploitation, output file writing, threading, proxy support, timeout control, and manual token input. Primary exploit capability: authenticated web exploitation over HTTP(S) against WordPress endpoints. The exploit is not framework-based and is not merely a scanner; it is intended to achieve real privilege escalation and account takeover. It appears mature enough to be considered OPERATIONAL because it automates the exploitation chain and supports bulk execution, but it does not expose a generalized post-exploitation payload beyond credential takeover. Fingerprintable targets include standard WordPress login/admin/REST endpoints and the LatePoint ability endpoint /wp-json/wp/v2/abilities/latepoint/connect-customer-to-wp-user. The README also documents the vulnerable code path and mitigation guidance, confirming the exploit's purpose and target conditions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation vulnerability in the LatePoint – Calendar Booking Plugin for Appointments and Events for WordPress caused by a missing authorization check, allowing authenticated attackers with the latepoint_agent role to take over administrator accounts and achieve full site takeover.
A privilege escalation vulnerability in the LatePoint WordPress booking plugin caused by a missing role verification in the connect-customer-to-wp-user ability, allowing a latepoint_agent user to take over an administrator account.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.