CVE-2026-7652
LatePoint – Calendar Booking Plugin for Appointments and Events
Minimum safe version
5.5.1
Update to 5.5.1 or later to address 25 fixable vulnerabilities
CVE-2026-7457
CVE-2026-7448
CVE-2026-7332
CVE-2026-6741
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
CVE-2026-5234
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure
LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import
LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting
LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVE-2026-32533
CVE-2025-14873
LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function
LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function
LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting
LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion
Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference
CVE-2025-30836
CVE-2024-8911
CVE-2024-8943
WordPress LatePoint plugin <= 4.9.91 - Cross Site Scripting (XSS) vulnerability
WordPress LatePoint plugin <= 4.9.91 - Cross Site Request Forgery (CSRF) vulnerability
CVE-2024-2472