← WordPress Vulnerabilities
WordPress security by component

LatePoint – Calendar Booking Plugin for Appointments and Events

LatePoint – Calendar Booking Plugin for Appointments and Events manages appointment scheduling, service bookings, staff availability, customer information, and calendar-based reservations in WordPress.

LatePoint – Calendar Booking Plugin for Appointments and Events (latepoint) is a WordPress plugin with 32 published CVE records in this archive. The latest tracked vulnerability was published Sep 18, 2026; the highest published CVSS base score is 9.8.

Plugin slug: latepoint

CVE-2026-13471: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress: LatePoint agents can access and delete other agents' bookings

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID. This vulnerability is only exploitable when an administrator has enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in the plugin settings. The Abilities API settings are required; the export does not give the full REST route. Its described deletion impact goes beyond a read-only interpretation of the score. Affected versions reported by the CNA: <= 5.6.3. No fixed release is confirmed for this CVE in this review.

PublishedSep 18, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for latepoint
Safe version
Sep 18, 2026 CVE-2026-13471
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress: LatePoint agents can access and delete other agents' bookings
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers, with LatePoint Agent-level access and above, to read bookings and customer PII (full name, email, phone, and notes) assigned to other LatePoint agents, and delete arbitrary bookings by supplying any booking ID. This vulnerability is only exploitable when an administrator has enabled the Abilities API toggles (latepoint_abilities_api, latepoint_abilities_api_delete, and/or latepoint_abilities_api_edit) in the plugin settings. The Abilities API settings are required; the export does not give the full REST route. Its described deletion impact goes beyond a read-only interpretation of the score. Affected versions reported by the CNA: <= 5.6.3. No fixed release is confirmed for this CVE in this review.
See mitigation notes
CVE4.3
NVDPending
Sep 18, 2026 CVE-2026-18441
LatePoint guest checkout exposes other customers' personal information
LatePoint through 5.6.9 is affected by an insecure direct object reference in set_customer_object. When customer authentication is disabled and guest checkout is enabled, an unauthenticated attacker can vary the customer[id] parameter and retrieve other customers' first names, last names, email addresses and phone numbers because the selected customer is not properly authorized. This is a customer-data disclosure, not an established account-takeover or modification path. The export does not identify a complete request route. Its description explicitly allows unauthenticated access under the guest-checkout condition, despite the CNA CVSS vector recording PR:L; the configuration-dependent description is retained here.
See mitigation notes
CVE4.3
NVDPending
Aug 06, 2026 CVE-2026-5391
LatePoint permits stored XSS through latepoint_resources
A logged-in Contributor can place script content in the btn_wrapper_classes attribute of the [latepoint_resources] shortcode in LatePoint 5.3.2 and earlier. In shortcode_latepoint_resources(), the locations branch inserts the value into a div class attribute without escaping, so the stored script runs when a visitor opens the page. Version 5.4.0 escapes the value with esc_attr().
5.4.0
CVE6.4
NVDPending
Jul 13, 2026 CVE-2026-57714
LatePoint: SQL injection
LatePoint is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.6.3.
5.6.4
CVE9.3
NVDPending
Jul 03, 2026 CVE-2026-11398
LatePoint – Calendar Booking Plugin for Appointments and Events: A security weakness
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.6.1.
See mitigation notes
CVE5.3
NVDPending
Jul 02, 2026 CVE-2026-12657
LatePoint – Calendar Booking Plugin for Appointments and Events: Broken access control
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 5.6.2.
See mitigation notes
CVE5.3
NVDPending
Jul 01, 2026 CVE-2026-13228
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.6.3.
See mitigation notes
CVE8.8
NVDPending
Jun 16, 2026 CVE-2026-8176
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.5.1.
See mitigation notes
CVE7.5
NVDPending
Jun 15, 2026 CVE-2026-49083
LatePoint: Privilege escalation or authentication bypass
LatePoint is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.5.1.
5.5.2
CVE7.5
NVDPending
Jun 06, 2026 CVE-2026-9719
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site request forgery
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 5.6.0.
See mitigation notes
CVE4.3
NVDPending
May 14, 2026 CVE-2026-5365
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site request forgery
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 5.3.2.
See mitigation notes
CVE4.3
NVDPending
May 09, 2026 CVE-2026-7652
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.5.0.
See mitigation notes
CVE5.3
NVDPending
May 06, 2026 CVE-2026-7457
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated customer account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.5.0.
See mitigation notes
CVE6.4
NVDPending
May 06, 2026 CVE-2026-7332
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.5.0.
See mitigation notes
CVE7.2
NVDPending
Apr 27, 2026 CVE-2026-6741
LatePoint – Calendar Booking Plugin for Appointments and Events: Privilege escalation or authentication bypass
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.4.1.
See mitigation notes
CVE8.8
NVDPending
Apr 17, 2026 CVE-2026-5234
LatePoint – Calendar Booking Plugin for Appointments and Events: Broken access control
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 5.3.2.
See mitigation notes
CVE5.3
NVDPending
Apr 08, 2026 CVE-2026-4785
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.3.0.
See mitigation notes
CVE6.4
NVDPending
Mar 25, 2026 CVE-2026-32533
LatePoint: A security weakness
LatePoint is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 5.2.6.
5.2.7
CVE6.5
NVDPending
Feb 12, 2026 CVE-2026-1537
LatePoint – Calendar Booking Plugin for Appointments and Events: A security weakness
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 03, 2026 CVE-2026-0617
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Sep 30, 2025 CVE-2025-7052
LatePoint: Cross-site request forgery
LatePoint is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
Sep 30, 2025 CVE-2025-7038
LatePoint: Privilege escalation or authentication bypass
LatePoint is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.2
NVDPending
Sep 30, 2025 CVE-2025-6941
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Sep 30, 2025 CVE-2025-6815
LatePoint – Calendar Booking Plugin for Appointments and Events: Cross-site scripting
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVDPending
Aug 13, 2025 CVE-2025-6715
LatePoint: Filesystem traversal
LatePoint is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVDPending
May 14, 2025 CVE-2025-3769
LatePoint – Calendar Booking Plugin for Appointments and Events: Broken access control
LatePoint – Calendar Booking Plugin for Appointments and Events is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE5.3
NVDPending
Mar 27, 2025 CVE-2025-30836
LatePoint: Cross-site scripting
LatePoint is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 21, 2024 CVE-2024-43945
LatePoint: Cross-site request forgery
LatePoint is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD8.8
Oct 08, 2024 CVE-2024-8943
LatePoint: Privilege escalation or authentication bypass
LatePoint is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Oct 08, 2024 CVE-2024-8911
LatePoint: SQL injection
LatePoint is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Sep 18, 2024 CVE-2024-43992
LatePoint: Cross-site scripting
LatePoint is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 14, 2024 CVE-2024-2472
LatePoint Plugin: A security weakness
LatePoint Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.1
NVDPending