Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LatePoint – Calendar Booking Plugin for Appointments and Events — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in LatePoint – Calendar Booking Plugin for Appointments and Events, with AI-generated Chinese analysis, references, and POCs.

LatePoint, a calendar booking plugin for appointments and events by LatePoint.net, is the focus of this vulnerability aggregation page covering common weakness categories. This collection gathers security reports, advisories, and identified flaws affecting the software, spanning from its initial release through current versions to provide a comprehensive historical context. Here, security professionals and administrators can track vendor advisories as they are published, understand the specific weakness classes that impact appointment scheduling systems, and look up the product's vulnerability history to assess risk exposure over time. The data is organized to facilitate easy navigation through disclosed issues, allowing users to see how the vendor responds to security findings and patches identified weaknesses. By aggregating these records in one location, the page supports informed decision-making regarding plugin updates and security configurations. Readers can examine the timeline of vulnerabilities to identify patterns or recurring issues within the codebase, which is essential for maintaining a secure web environment. This resource serves as a centralized reference point for understanding the security posture of LatePoint, enabling stakeholders to evaluate whether the product meets their organizational security standards. The information presented is derived from official advisories and public disclosures, ensuring accuracy and reliability for those managing WordPress sites that rely on this booking solution.

Vendor: latepoint

CVE IDTitleCVSSSeverityPublished
CVE-2026-5356 LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass CWE-862 7.5 High2026-07-08
CVE-2026-11398 LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step CWE-862 5.3 Medium2026-07-03
CVE-2026-12657 LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter CWE-639 5.3 Medium2026-07-02
CVE-2026-13228 LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter CWE-269 8.8 High2026-07-01
CVE-2026-8176 LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset CWE-269 7.5 High2026-06-16
CVE-2026-9719 LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action CWE-352 4.3 Medium2026-06-05
CVE-2026-5365 LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route CWE-352 4.3 Medium2026-05-14
CVE-2026-7652 LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism CWE-640 5.3 Medium2026-05-09
CVE-2026-7332 LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter CWE-79 7.2 High2026-05-06
CVE-2026-7457 LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update CWE-79 6.4 Medium2026-05-06
CVE-2026-6741 LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability CWE-269 8.8 High2026-04-27
CVE-2026-5234 LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID CWE-639 5.3 Medium2026-04-17
CVE-2026-4785 LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2026-04-08
CVE-2026-2324 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting CWE-352 6.1 Medium2026-03-11
CVE-2026-1487 LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import CWE-89 6.5 Medium2026-03-03
CVE-2026-1566 LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation CWE-269 8.8 High2026-03-02
CVE-2025-14873 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery CWE-352 4.3 Medium2026-02-14
CVE-2026-1537 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure CWE-862 5.3 Medium2026-02-12
CVE-2026-0617 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2026-02-03
CVE-2025-7052 LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function CWE-352 8.8 High2025-09-30
CVE-2025-7038 LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function CWE-288 8.2 High2025-09-30
CVE-2025-6941 LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2025-09-30
CVE-2025-6815 LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 5.5 Medium2025-09-30
CVE-2025-3769 Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference CWE-639 5.3 Medium2025-05-14

All 24 known CVE vulnerabilities affecting LatePoint – Calendar Booking Plugin for Appointments and Events with full Chinese analysis, references, and POCs where available.