CVE-2026-32533: WordPress LatePoint plugin <= 5.2.6 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through <= 5.2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32533?
CVE-2026-32533 is rated as a high-severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-32533?
To fix CVE-2026-32533, update the LatePoint plugin to version 5.2.7 or later.
What types of systems are affected by CVE-2026-32533?
CVE-2026-32533 affects WordPress installations using the LatePoint plugin version 5.2.6 and below.
What is the nature of the vulnerability in CVE-2026-32533?
CVE-2026-32533 is an Insecure Direct Object References (IDOR) vulnerability that allows bypassing authorization controls.
Who is affected by CVE-2026-32533?
Any user or administrator utilizing the LatePoint plugin for WordPress versions up to 5.2.6 is potentially affected by CVE-2026-32533.