Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LatePoint – Calendar Booking Plugin for Appointments and Events — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in LatePoint – Calendar Booking Plugin for Appointments and Events, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specifically affecting the LatePoint – Calendar Booking Plugin for Appointments and Events, categorizing them by Common Weakness Enumeration identifiers. It collects disclosed security flaws associated with this product, covering public advisories and patch releases spanning from the plugin’s initial release through the most recent updates. Readers can use this aggregation to track the vendor’s historical security posture, understand specific weakness classes such as cross-site scripting or access control failures, and review the complete vulnerability timeline for the product without searching individual database entries. The collection focuses on verified issues that impact appointment scheduling, event management, and user session handling within the plugin’s codebase.

Vendor: latepoint

CVE ID Title CVSS Severity Published
CVE-2026-5356 LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass CWE-862 7.5 High 2026-07-08
CVE-2026-11398 LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step CWE-862 5.3 Medium 2026-07-03
CVE-2026-12657 LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter CWE-639 5.3 Medium 2026-07-02
CVE-2026-13228 LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter CWE-269 8.8 High 2026-07-01
CVE-2026-8176 LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset CWE-269 7.5 High 2026-06-16
CVE-2026-9719 LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action CWE-352 4.3 Medium 2026-06-05
CVE-2026-5365 LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route CWE-352 4.3 Medium 2026-05-14
CVE-2026-7652 LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism CWE-640 5.3 Medium 2026-05-09
CVE-2026-7332 LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter CWE-79 7.2 High 2026-05-06
CVE-2026-7457 LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update CWE-79 6.4 Medium 2026-05-06
CVE-2026-6741 LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability CWE-269 8.8 High 2026-04-27
CVE-2026-5234 LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID CWE-639 5.3 Medium 2026-04-17
CVE-2026-4785 LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2026-04-08
CVE-2026-2324 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting CWE-352 6.1 Medium 2026-03-11
CVE-2026-1487 LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import CWE-89 6.5 Medium 2026-03-03
CVE-2026-1566 LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation CWE-269 8.8 High 2026-03-02
CVE-2025-14873 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery CWE-352 4.3 Medium 2026-02-14
CVE-2026-1537 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure CWE-862 5.3 Medium 2026-02-12
CVE-2026-0617 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2026-02-03
CVE-2025-7052 LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function CWE-352 8.8 High 2025-09-30
CVE-2025-7038 LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function CWE-288 8.2 High 2025-09-30
CVE-2025-6941 LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2025-09-30
CVE-2025-6815 LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 5.5 Medium 2025-09-30
CVE-2025-3769 Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference CWE-639 5.3 Medium 2025-05-14

All 24 known CVE vulnerabilities affecting LatePoint – Calendar Booking Plugin for Appointments and Events with full Chinese analysis, references, and POCs where available.