Arbitrary Shortcode Execution in LatePoint Appointment Booking Plugin for WordPress
CVE-2026-92966
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-92966?
The Appointment Booking Plugin β LatePoint for WordPress is affected by a security flaw that allows unauthenticated users to execute arbitrary shortcodes. This vulnerability arises from the plugin's failure to properly validate user input during the appointment booking process. An attacker can insert malicious shortcodes that will be executed by the WordPress core, compromising the integrity of the site. Specifically, this issue affects all versions up to and including 5.7.0, where the Customer Cabinet block may inadvertently render stored user data that includes the malicious shortcode, creating a potential security risk for site administrators and users.
Affected Version(s)
Appointment Booking Plugin β LatePoint | Calendar & Scheduling for WordPress 0 <= 5.7.0