CVE-2026-17538 | LatePoint Plugin up to 5.6.9 on WordPress Customer Data Merge process_step_customer contact_merge authorization
A vulnerability identified as critical has been detected in LatePoint Plugin up to 5.6.9 on WordPress. This impacts the function process_step_customer of the component Customer Data Merge. The manipulation of the argument contact_merge leads to authorization bypass.
This vulnerability is listed as CVE-2026-17538. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More