LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint · plugin
Known security vulnerabilities for LatePoint – Calendar Booking Plugin for Appointments and Events. Find out in seconds which version runs on your site with WP Lens.
32 known vulnerabilities
2 critical · 3 with public exploit code · latest Oct 1, 2026
Vulnerabilities
- Critical 9.3
WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability
- Critical 9.1
Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field
- High 8.8
LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
- High 8.8
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
- High 8.8
LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function
- High 8.8
WordPress LatePoint plugin <= 4.9.91 - Cross Site Request Forgery (CSRF) vulnerability
- High 8.2
LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function
- High 7.5
LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
- High 7.5
LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Ca
- High 7.5
WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability
- High 7.2
LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter
- High 7.2
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting
- Medium 6.5
WordPress LatePoint plugin <= 5.2.6 - Insecure Direct Object References (IDOR) vulnerability
- Medium 6.5
WordPress LatePoint plugin <= 5.1.6 - Cross Site Scripting (XSS) vulnerability
- Medium 6.4
LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
- Medium 6.4
LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update
- Medium 6.4
LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 6.4
LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 6.1
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scrip
- Medium 5.5
LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Medium 5.4
WordPress LatePoint plugin <= 4.9.91 - Cross Site Scripting (XSS) vulnerability
- Medium 5.3
LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
- Medium 5.3
LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
- Medium 5.3
LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism
- Medium 5.3
LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
- Medium 5.3
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure
- Medium 5.3
Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference
- Medium 4.3
LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities R
- Medium 4.3
LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]'
- Medium 4.3
LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action
- Medium 4.3
LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route
- Medium 4.3
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery