Arbitrary Shortcode Execution in LatePoint Appointment Booking Plugin for WordPress
CVE-2026-92966

9.1CRITICAL

What is CVE-2026-92966?

The Appointment Booking Plugin – LatePoint for WordPress is affected by a security flaw that allows unauthenticated users to execute arbitrary shortcodes. This vulnerability arises from the plugin's failure to properly validate user input during the appointment booking process. An attacker can insert malicious shortcodes that will be executed by the WordPress core, compromising the integrity of the site. Specifically, this issue affects all versions up to and including 5.7.0, where the Customer Cabinet block may inadvertently render stored user data that includes the malicious shortcode, creating a potential security risk for site administrators and users.

Affected Version(s)

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0 <= 5.7.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hashiramasenju333
.