Перейти к содержимому
Noroxi

LatePoint – Calendar Booking Plugin for Appointments and Events

latepoint · плагин

Известные уязвимости для LatePoint – Calendar Booking Plugin for Appointments and Events. Узнайте за секунды, какая версия работает на вашем сайте, с WP Lens.

32 известных уязвимостей

2 критичных · 3 с публичным эксплойтом · последняя 1 окт. 2026 г.

Уязвимости

  • CVE-2026-57714

    WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability

    Критич. 9.3
  • CVE-2026-92966

    Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field

    Критич. 9.1
  • CVE-2026-13228

    LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter

    Высокий 8.8
  • CVE-2026-6741

    LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability

    Высокий 8.8
  • CVE-2025-7052

    LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function

    Высокий 8.8
  • CVE-2024-43945

    WordPress LatePoint plugin <= 4.9.91 - Cross Site Request Forgery (CSRF) vulnerability

    Высокий 8.8
  • CVE-2025-7038

    LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function

    Высокий 8.2
  • CVE-2026-5356

    LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass

    Высокий 7.5
  • CVE-2026-8176

    LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Ca

    Высокий 7.5
  • CVE-2026-49083

    WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability

    Высокий 7.5
  • CVE-2026-7332

    LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter

    Высокий 7.2
  • CVE-2026-0617

    LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting

    Высокий 7.2
  • CVE-2026-32533

    WordPress LatePoint plugin <= 5.2.6 - Insecure Direct Object References (IDOR) vulnerability

    Средний 6.5
  • CVE-2025-30836

    WordPress LatePoint plugin <= 5.1.6 - Cross Site Scripting (XSS) vulnerability

    Средний 6.5
  • CVE-2026-5391

    LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

    Средний 6.4
  • CVE-2026-7457

    LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update

    Средний 6.4
  • CVE-2026-4785

    LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Средний 6.4
  • CVE-2025-6941

    LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Средний 6.4
  • CVE-2026-2324

    LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scrip

    Средний 6.1
  • CVE-2025-6815

    LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Средний 5.5
  • CVE-2024-43992

    WordPress LatePoint plugin <= 4.9.91 - Cross Site Scripting (XSS) vulnerability

    Средний 5.4
  • CVE-2026-11398

    LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step

    Средний 5.3
  • CVE-2026-12657

    LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter

    Средний 5.3
  • CVE-2026-7652

    LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism

    Средний 5.3
  • CVE-2026-5234

    LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID

    Средний 5.3
  • CVE-2026-1537

    LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure

    Средний 5.3
  • CVE-2025-3769

    Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference

    Средний 5.3
  • CVE-2026-13471

    LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities R

    Средний 4.3
  • CVE-2026-18441

    LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]'

    Средний 4.3
  • CVE-2026-9719

    LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

    Средний 4.3
  • CVE-2026-5365

    LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route

    Средний 4.3
  • CVE-2025-14873

    LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery

    Средний 4.3

← К каталогу