A SQL Injection vulnerability was discovered in LatePoint, a WordPress plugin, affecting versions from n/a through 5.6.3. This issue allows for Blind SQL Injection, with a CVSS score of 9.3 and a severity of CRITICAL. The vulnerability is caused by improper neutralization of special elements used in an SQL command. Users of LatePoint should be aware of this vulnerability and take immediate action to prote [truncated]
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This vulnerability allows unauthenticated attackers to pay an arbitrary amount by supplying a previously succeeded PaymentIntent token due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent I [truncated]
CVE-2026-8176 is a Privilege Escalation vulnerability in the LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress. The vulnerability affects versions up to, and including, 5.5.1. An authenticated Agent (Agent+) can exploit this vulnerability to elevate their privileges to Administrator without invoking an Administrator-only API.
CVE-2026-49083 is a HIGH severity vulnerability (CVSS Score: 7.5) in the LatePoint plugin versions <= 5.5.1. This vulnerability allows for contributor privilege escalation. The CVE was published on 2026-06-15T21:17:20.150Z and last modified on 2026-06-15T21:24:32.790Z.
A Cross-Site Request Forgery (CSRF) vulnerability exists in the LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress. This vulnerability affects all versions up to, and including, 5.6.0. The issue arises from missing or incorrect nonce validation on the change_status function, allowing unauthenticated attackers to change the status of arbitrary invoices, including marking u [truncated]
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping when the 'items' parameter is set to 'bundles'. This makes it possible for authenticated attackers, with contributor- [truncated]