Cross-Site Scripting
9 records25%First: 2024. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 36 vulnerability records associated with Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress, published between 2024 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2024 | 5 | |
| 2025 | 7 | |
| 2026 | 24 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 11.1% |
| High | 12 | 33.3% |
| Medium | 20 | 55.6% |
First: 2024. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2026.
First: 2026. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2025.
First: 2025. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
5.6.45.4.15.6.25.6.35.5.25.6.15.4.05.5.15.4.25.3.15.2.75.2.85.2.65.2.05.1.945.1.935.1.75.0.135.0.124.9.9.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-5.6.3 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.3 - Unauthenticated SQL Injection | July 8, 2026 | 5.6.4 | High |
*-5.4.0 | LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass | July 7, 2026 | 5.4.1 | High |
*-5.6.1 | LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step | July 2, 2026 | 5.6.2 | Medium |
*-5.6.2 | LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter | July 1, 2026 | 5.6.3 | Medium |
*-5.6.3 | LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter | June 30, 2026 | 5.6.4 | High |
*-5.6.2 | LatePoint <= 5.6.2 - Cross-Site Request Forgery | June 25, 2026 | 5.6.3 | Medium |
*-5.5.1 | LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset | June 15, 2026 | 5.5.2 | High |
*-5.6.0 | LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action | June 5, 2026 | 5.6.1 | Medium |
*-5.5.1 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege Escalation | June 5, 2026 | 5.5.2 | High |
*-5.3.2 | LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route | May 13, 2026 | 5.4.0 | Medium |
*-5.5.0 | LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism | May 8, 2026 | 5.5.1 | Medium |
*-5.5.0 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting | May 6, 2026 | 5.5.1 | High |
*-5.5.0 | LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter | May 5, 2026 | 5.5.1 | High |
*-5.5.0 | LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update | May 5, 2026 | 5.5.1 | Medium |
*-5.4.1 | LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability | April 27, 2026 | 5.4.2 | High |
*-5.3.2 | LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID | April 16, 2026 | 5.4.0 | Medium |
*-5.3.0 | LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | April 7, 2026 | 5.3.1 | Medium |
*-5.2.6 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object Reference | March 23, 2026 | 5.2.7 | Medium |
*-5.2.7 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting | March 10, 2026 | 5.2.8 | Medium |
*-5.2.7 | LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import | March 2, 2026 | 5.2.8 | Medium |
*-5.2.7 | LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation | March 2, 2026 | 5.2.8 | High |
*-5.2.5 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery | February 13, 2026 | 5.2.6 | Medium |
*-5.2.6 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure | February 11, 2026 | 5.2.7 | Medium |
*-5.2.5 | LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting | February 2, 2026 | 5.2.6 | High |
*-5.1.94 | LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function | September 29, 2025 | 5.2.0 | High |
Selected source records
Published: July 8, 2026
Published: July 7, 2026
Published: July 2, 2026
Published: July 1, 2026
Published: June 30, 2026
Published: June 25, 2026
Published: June 15, 2026
Published: June 5, 2026
Published: September 20, 2024
Published: September 24, 2024
Published: July 23, 2025
Published: June 13, 2024
Published: April 27, 2026
Published: June 30, 2026
Published: March 2, 2026
Published: September 29, 2025
Published: August 29, 2024
Published: August 26, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.