LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action
CVE-2026-9719
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-9719?
The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the change_status function. This makes it possible for unauthenticated attackers to change the status of arbitrary invoices β including marking unpaid invoices as paid β without administrator consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Version(s)
LatePoint β Calendar Booking Plugin for Appointments and Events 0 <= 5.6.0