SQL Injection Vulnerability in Appointment Booking Plugin for WordPress by LatePoint
CVE-2026-96662

7.5HIGH

What is CVE-2026-96662?

The Appointment Booking Plugin – LatePoint for WordPress is exposed to a SQL Injection vulnerability through the 'booking[service_id]' parameter. Due to inadequate input escaping and preparation in SQL queries, this vulnerability allows unauthenticated attackers to execute arbitrary SQL commands. This flaw can lead to the unauthorized extraction of sensitive data from the database, significantly jeopardizing the security of affected WordPress installations.

Affected Version(s)

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 0 <= 5.7.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zickzick2
.