All verified exploits

CVE-2026-1566 Agent-to-Admin Privilege Escalation via wordpress_user_id

Pentest high LatePoint Added cve-verified-cve-2026-1566

Detects LatePoint WordPress plugin versions 5.2.7 and earlier where Agent-level users can manipulate the wordpress_user_id parameter during customer creation to link customers to administrator accounts. Combined with the built-in password reset, this allows full WordPress admin takeover from a low-privileged Agent account.

Is your app exploitable through CVE-2026-1566?

Scan your domain free