LatePoint – Calendar Booking Plugin for Appointments and Events
LatePoint – Calendar Booking Plugin for Appointments and Events manages appointment scheduling, service bookings, staff availability, customer information, and calendar-based reservations in WordPress.
LatePoint – Calendar Booking Plugin for Appointments and Events (latepoint) is a WordPress plugin with 32 published CVE records in this archive. The latest tracked vulnerability was published Sep 18, 2026; the highest published CVSS base score is 9.8.
latepointCVE-2026-13471: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress: LatePoint agents can access and delete other agents' bookings
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID. This vulnerability is only exploitable when an administrator has enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in the plugin settings. The Abilities API settings are required; the export does not give the full REST route. Its described deletion impact goes beyond a read-only interpretation of the score. Affected versions reported by the CNA: <= 5.6.3. No fixed release is confirmed for this CVE in this review.
| Safe version |
|
||
|---|---|---|---|
| Sep 18, 2026 |
CVE-2026-13471
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress: LatePoint agents can access and delete other agents' bookings
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID. This vulnerability is only exploitable when an administrator has enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in the plugin settings. The Abilities API settings are required; the export does not give the full REST route. Its described deletion impact goes beyond a read-only interpretation of the score. Affected versions reported by the CNA: <= 5.6.3. No fixed release is confirmed for this CVE in this review.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 18, 2026 |
CVE-2026-18441
LatePoint guest checkout exposes other customers' personal information
LatePoint through 5.6.9 is affected by an insecure direct object reference in set_customer_object. When customer authentication is disabled and guest checkout is enabled, an unauthenticated attacker can vary the customer[id] parameter and retrieve other customers' first names, last names, email addresses and phone numbers because the selected customer is not properly authorized. This is a customer-data disclosure, not an established account-takeover or modification path. The export does not identify a complete request route. Its description explicitly allows unauthenticated access under the guest-checkout condition, despite the CNA CVSS vector recording PR:L; the configuration-dependent description is retained here.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 06, 2026 |
CVE-2026-5391
LatePoint permits stored XSS through latepoint_resources
A logged-in Contributor can place script content in the btn_wrapper_classes attribute of the [latepoint_resources] shortcode in LatePoint 5.3.2 and earlier. In shortcode_latepoint_resources(), the locations branch inserts the value into a div class attribute without escaping, so the stored script runs when a visitor opens the page. Version 5.4.0 escapes the value with esc_attr().
|
5.4.0 |
CVE6.4
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57714
LatePoint: SQL injection
LatePoint is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.6.3.
|
5.6.4 |
CVE9.3
NVDPending
|
| Jul 03, 2026 |
CVE-2026-11398
LatePoint – Calendar Booking Plugin for Appointments and Events: A security weakness
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.6.1.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 02, 2026 |
CVE-2026-12657
LatePoint – Calendar Booking Plugin for Appointments and Events: Broken access control
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 5.6.2.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 01, 2026 |
CVE-2026-13228
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.6.3.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jun 16, 2026 |
CVE-2026-8176
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.5.1.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-49083
LatePoint: Privilege escalation or authentication bypass
LatePoint is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.5.1.
|
5.5.2 |
CVE7.5
NVDPending
|
| Jun 06, 2026 |
CVE-2026-9719
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site request forgery
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 5.6.0.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 14, 2026 |
CVE-2026-5365
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site request forgery
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 5.3.2.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 09, 2026 |
CVE-2026-7652
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.5.0.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 06, 2026 |
CVE-2026-7457
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated customer account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.5.0.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 06, 2026 |
CVE-2026-7332
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.5.0.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Apr 27, 2026 |
CVE-2026-6741
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.4.1.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 17, 2026 |
CVE-2026-5234
LatePoint – Calendar Booking Plugin for Appointments and Events: Broken access control
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 5.3.2.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-4785
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.3.0.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 25, 2026 |
CVE-2026-32533
LatePoint: A security weakness
LatePoint is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 5.2.6.
|
5.2.7 |
CVE6.5
NVDPending
|
| Feb 12, 2026 |
CVE-2026-1537
LatePoint – Calendar Booking Plugin for Appointments and Events: A security weakness
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 03, 2026 |
CVE-2026-0617
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Sep 30, 2025 |
CVE-2025-7052
LatePoint: Cross-site request forgery
LatePoint is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Sep 30, 2025 |
CVE-2025-7038
LatePoint: Privilege escalation or authentication bypass
LatePoint is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.2
NVDPending
|
| Sep 30, 2025 |
CVE-2025-6941
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 30, 2025 |
CVE-2025-6815
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVDPending
|
| Aug 13, 2025 |
CVE-2025-6715
LatePoint: Filesystem traversal
LatePoint is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE9.8
NVDPending
|
| May 14, 2025 |
CVE-2025-3769
LatePoint – Calendar Booking Plugin for Appointments and Events: Broken access control
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30836
LatePoint: Cross-site scripting
LatePoint is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 21, 2024 |
CVE-2024-43945
LatePoint: Cross-site request forgery
LatePoint is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD8.8
|
| Oct 08, 2024 |
CVE-2024-8943
LatePoint: Privilege escalation or authentication bypass
LatePoint is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Oct 08, 2024 |
CVE-2024-8911
LatePoint: SQL injection
LatePoint is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Sep 18, 2024 |
CVE-2024-43992
LatePoint: Cross-site scripting
LatePoint is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 14, 2024 |
CVE-2024-2472
LatePoint Plugin: A security weakness
LatePoint Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.1
NVDPending
|