Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 36 vulnerability records associated with Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress, published between 2024 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

36Total records
4Critical
12High
20Medium
0Low
0Informational
34Patched records
2Currently marked unpatched
2024-06-13First disclosure
2026-07-08Latest disclosure
36 of 36CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202455 records
202577 records
20262424 records

Severity Breakdown

SeverityRecordsShare
Critical411.1%
High1233.3%
Medium2055.6%

Vulnerability-Type Breakdown

Cross-Site Scripting

9 records25%

First: 2024. Latest: 2026.

Missing Authorization

8 records22.2%

First: 2024. Latest: 2026.

CSRF

7 records19.4%

First: 2024. Latest: 2026.

Privilege Escalation

5 records13.9%

First: 2026. Latest: 2026.

SQL Injection

3 records8.3%

First: 2024. Latest: 2026.

Authentication Bypass

2 records5.6%

First: 2024. Latest: 2025.

Other

2 records5.6%

First: 2025. Latest: 2026.

Patch Status

Patched
34
Currently marked unpatched
2
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 5.6.4
  • 5.4.1
  • 5.6.2
  • 5.6.3
  • 5.5.2
  • 5.6.1
  • 5.4.0
  • 5.5.1
  • 5.4.2
  • 5.3.1
  • 5.2.7
  • 5.2.8
  • 5.2.6
  • 5.2.0
  • 5.1.94
  • 5.1.93
  • 5.1.7
  • 5.0.13
  • 5.0.12
  • 4.9.9.1

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-5.6.3Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.3 - Unauthenticated SQL InjectionJuly 8, 20265.6.4High
*-5.4.0LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding BypassJuly 7, 20265.4.1High
*-5.6.1LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer StepJuly 2, 20265.6.2Medium
*-5.6.2LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' ParameterJuly 1, 20265.6.3Medium
*-5.6.3LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' ParameterJune 30, 20265.6.4High
*-5.6.2LatePoint <= 5.6.2 - Cross-Site Request ForgeryJune 25, 20265.6.3Medium
*-5.5.1LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password ResetJune 15, 20265.5.2High
*-5.6.0LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status ActionJune 5, 20265.6.1Medium
*-5.5.1LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege EscalationJune 5, 20265.5.2High
*-5.3.2LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX RouteMay 13, 20265.4.0Medium
*-5.5.0LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery MechanismMay 8, 20265.5.1Medium
*-5.5.0LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 - Unauthenticated Stored Cross-Site ScriptingMay 6, 20265.5.1High
*-5.5.0LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' ParameterMay 5, 20265.5.1High
*-5.5.0LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile UpdateMay 5, 20265.5.1Medium
*-5.4.1LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' AbilityApril 27, 20265.4.2High
*-5.3.2LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice IDApril 16, 20265.4.0Medium
*-5.3.0LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeApril 7, 20265.3.1Medium
*-5.2.6LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object ReferenceMarch 23, 20265.2.7Medium
*-5.2.7LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site ScriptingMarch 10, 20265.2.8Medium
*-5.2.7LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON ImportMarch 2, 20265.2.8Medium
*-5.2.7LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege EscalationMarch 2, 20265.2.8High
*-5.2.5LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request ForgeryFebruary 13, 20265.2.6Medium
*-5.2.6LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details ExposureFebruary 11, 20265.2.7Medium
*-5.2.5LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site ScriptingFebruary 2, 20265.2.6High
*-5.1.94LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() FunctionSeptember 29, 20255.2.0High

Selected source records

Latest Records

HighCVE-2026-57714

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.3 - Unauthenticated SQL Injection

Published: July 8, 2026

Affected versions
*-5.6.3
Patched versions
5.6.4
Original Wordfence record
HighCVE-2026-5356

LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass

Published: July 7, 2026

Affected versions
*-5.4.0
Patched versions
5.4.1
Original Wordfence record
MediumCVE-2026-11398

LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step

Published: July 2, 2026

Affected versions
*-5.6.1
Patched versions
5.6.2
Original Wordfence record
MediumCVE-2026-12657

LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter

Published: July 1, 2026

Affected versions
*-5.6.2
Patched versions
5.6.3
Original Wordfence record
HighCVE-2026-13228

LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter

Published: June 30, 2026

Affected versions
*-5.6.3
Patched versions
5.6.4
Original Wordfence record
MediumCVE-2026-11866

LatePoint <= 5.6.2 - Cross-Site Request Forgery

Published: June 25, 2026

Affected versions
*-5.6.2
Patched versions
5.6.3
Original Wordfence record
HighCVE-2026-8176

LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

Published: June 15, 2026

Affected versions
*-5.5.1
Patched versions
5.5.2
Original Wordfence record
MediumCVE-2026-9719

LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

Published: June 5, 2026

Affected versions
*-5.6.0
Patched versions
5.6.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-8911

LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection

Published: September 20, 2024

Affected versions
*-5.0.11
Patched versions
5.0.12
Original Wordfence record
CriticalCVE-2024-8943

LatePoint <= 5.0.12 - Authentication Bypass

Published: September 24, 2024

Affected versions
*-5.0.12
Patched versions
5.0.13
Original Wordfence record
CriticalCVE-2025-6715

LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion

Published: July 23, 2025

Affected versions
*-5.1.93
Patched versions
5.1.94
Original Wordfence record
CriticalCVE-2024-2472

LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR

Published: June 13, 2024

Affected versions
*-4.9.9
Patched versions
4.9.9.1
Original Wordfence record
HighCVE-2026-6741

LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability

Published: April 27, 2026

Affected versions
*-5.4.1
Patched versions
5.4.2
Original Wordfence record
HighCVE-2026-13228

LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter

Published: June 30, 2026

Affected versions
*-5.6.3
Patched versions
5.6.4
Original Wordfence record
HighCVE-2026-1566

LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation

Published: March 2, 2026

Affected versions
*-5.2.7
Patched versions
5.2.8
Original Wordfence record
HighCVE-2025-7052

LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function

Published: September 29, 2025

Affected versions
*-5.1.94
Patched versions
5.2.0
Original Wordfence record

Currently Marked Unpatched Records

MediumCVE-2024-43992

LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Published: August 29, 2024

Affected versions
*-4.9.91
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2024-43945

LatePoint <= 4.9.91 - Cross-Site Request Forgery

Published: August 26, 2024

Affected versions
*-4.9.91
Patched versions
Not supplied
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory