Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

latepoint — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting latepoint. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Latepoint is a WordPress plugin designed to facilitate appointment scheduling and booking management for service-based businesses. Its widespread adoption has made it a frequent target for automated attacks, resulting in twenty-four recorded Common Vulnerabilities and Exposures (CVEs). Historically, the software has suffered from critical flaws including remote code execution, cross-site scripting, and SQL injection, often stemming from insufficient input validation and improper access controls. These vulnerabilities frequently allow unauthenticated attackers to escalate privileges or execute arbitrary commands on compromised servers. While no single catastrophic data breach has been publicly attributed solely to Latepoint, the high volume of exploitable bugs indicates systemic security deficiencies in its development lifecycle. Administrators are strongly advised to maintain strict patching schedules and monitor for unauthorized modifications to ensure the integrity of their booking infrastructure against these persistent threats.

CVE ID Title CVSS Severity Published
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress CWE-94 9.1 Critical 2026-10-01
CVE-2026-13471 LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking) — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress CWE-639 4.3 Medium 2026-09-18
CVE-2026-18441 LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress CWE-639 4.3 Medium 2026-09-17
CVE-2026-5391 LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress CWE-79 6.4 Medium 2026-08-06
CVE-2026-57714 WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability — LatePoint CWE-89 9.3 Critical 2026-07-13
CVE-2026-5356 LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-862 7.5 High 2026-07-08
CVE-2026-11398 LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-862 5.3 Medium 2026-07-03
CVE-2026-12657 LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-639 5.3 Medium 2026-07-02
CVE-2026-13228 LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-269 8.8 High 2026-07-01
CVE-2026-8176 LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-269 7.5 High 2026-06-16
CVE-2026-49083 WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability — LatePoint CWE-266 7.5 High 2026-06-15
CVE-2026-9719 LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-352 4.3 Medium 2026-06-05
CVE-2026-5365 LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-352 4.3 Medium 2026-05-14
CVE-2026-7652 LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-640 5.3 Medium 2026-05-09
CVE-2026-7332 LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-79 7.2 High 2026-05-06
CVE-2026-7457 LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-79 6.4 Medium 2026-05-06
CVE-2026-6741 LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-269 8.8 High 2026-04-27
CVE-2026-5234 LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-639 5.3 Medium 2026-04-17
CVE-2026-4785 LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-79 6.4 Medium 2026-04-08
CVE-2026-32533 WordPress LatePoint plugin <= 5.2.6 - Insecure Direct Object References (IDOR) vulnerability — LatePoint CWE-639 6.5 Medium 2026-03-25
CVE-2026-2324 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-352 6.1 Medium 2026-03-11
CVE-2026-1487 LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-89 6.5 Medium 2026-03-03
CVE-2026-1566 LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-269 8.8 High 2026-03-02
CVE-2025-14873 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-352 4.3 Medium 2026-02-14
CVE-2026-1537 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-862 5.3 Medium 2026-02-12
CVE-2026-0617 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-79 7.2 High 2026-02-03
CVE-2025-7038 LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-288 8.2 High 2025-09-30
CVE-2025-7052 LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-352 8.8 High 2025-09-30
CVE-2025-6941 LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-79 6.4 Medium 2025-09-30
CVE-2025-6815 LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting — LatePoint – Calendar Booking Plugin for Appointments and Events CWE-79 5.5 Medium 2025-09-30

This page lists every published CVE security advisory associated with latepoint. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.