plugin

Latepoint Vulnerabilities

49 known security issues reported for the Latepoint WordPress plugin. Most recent disclosed Aug 5, 2026.

4 critical 15 high 22 medium

Running Latepoint on your site? Check whether your installed version is affected.

Scan your site free

LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the 'locations' branch of the 'shortcode_latep...

CVSS:
6.4
Affected:
up to 5.3.2
Fixed in:
5.4.0
Disclosed:
Aug 5, 2026

CVE-2026-5391 on NVD →

LatePoint <= 5.6.7 - Missing Authorization to Unauthenticated Booking Object Mass Assignment

medium

The LatePoint plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.6.7. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.6.7
Fixed in:
5.6.8
Disclosed:
Jul 10, 2026

CVE-2026-15250 on NVD →

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.3 - Unauthenticated SQL Injection

high

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

CVSS:
7.5
Affected:
up to 5.6.3
Fixed in:
5.6.4
Disclosed:
Jul 8, 2026

CVE-2026-57714 on NVD →

LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. This makes it possible for unauthent...

CVSS:
7.5
Affected:
up to 5.4.0
Fixed in:
5.4.1
Disclosed:
Jul 7, 2026

CVE-2026-5356 on NVD →

LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attacker...

CVSS:
5.3
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Jul 2, 2026

CVE-2026-11398 on NVD →

LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers t...

CVSS:
5.3
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Jul 1, 2026

CVE-2026-12657 on NVD →

LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.6.3 This is due to an Insecure Direct Object Reference (IDOR) in the create_or_update() function of OsOrdersController, which allows an auth...

CVSS:
8.8
Affected:
up to 5.6.3
Fixed in:
5.6.4
Disclosed:
Jun 30, 2026

CVE-2026-13228 on NVD →

LatePoint <= 5.6.2 - Cross-Site Request Forgery

medium

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...

CVSS:
4.3
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Jun 25, 2026

CVE-2026-11866 on NVD →

LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's...

CVSS:
7.5
Affected:
up to 5.5.1
Fixed in:
5.5.2
Disclosed:
Jun 15, 2026

CVE-2026-8176 on NVD →

LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the change_status function. This makes it possible for unauthenticated attackers to ch...

CVSS:
4.3
Affected:
up to 5.6.0
Fixed in:
5.6.1
Disclosed:
Jun 5, 2026

CVE-2026-9719 on NVD →

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege Escalation

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to elevate their privileges to that of an administrator...

CVSS:
8.8
Affected:
up to 5.5.1
Fixed in:
5.5.2
Disclosed:
Jun 5, 2026

CVE-2026-49083 on NVD →

LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route

medium

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() function. This makes it possible for unauthenticated attackers to cancel a logged-in customer's bookings via a forged request,...

CVSS:
4.3
Affected:
up to 5.3.2
Fixed in:
5.4.0
Disclosed:
May 13, 2026

CVE-2026-5365 on NVD →

LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism

medium

The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due to the save_connected_wordpress_user() function propagating a LatePoint customer's email address to its linked WordPress...

CVSS:
5.3
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
May 8, 2026

CVE-2026-7652 on NVD →

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
7.2
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
May 6, 2026

CVE-2026-7448 on NVD →

LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
7.2
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
May 5, 2026

CVE-2026-7332 on NVD →

LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update

medium

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input sanitization on the customer cabinet profile update endpoint — where raw POST parameters (first_name, last_name, phone, notes) bypass sanitization because OsCustom...

CVSS:
6.4
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
May 5, 2026

CVE-2026-7457 on NVD →

LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires the customer__edit ca...

CVSS:
8.8
Affected:
up to 5.4.1
Fixed in:
5.4.2
Disclosed:
Apr 27, 2026

CVE-2026-6741 on NVD →

LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID

medium

The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no authentication required) and loads invoices...

CVSS:
5.3
Affected:
up to 5.3.2
Fixed in:
5.4.0
Disclosed:
Apr 16, 2026

CVE-2026-5234 on NVD →

LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping when the 'items' parameter is...

CVSS:
6.4
Affected:
up to 5.3.0
Fixed in:
5.3.1
Disclosed:
Apr 7, 2026

CVE-2026-4785 on NVD →

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.2.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and...

CVSS:
4.3
Affected:
up to 5.2.6
Fixed in:
5.2.7
Disclosed:
Mar 23, 2026

CVE-2026-32533 on NVD →

LatePoint - WordPress LatePoint - Calendar Booking Plugin for Appointments and Events plugin <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting vulnerability

high

WordPress LatePoint - Calendar Booking Plugin for Appointments and Events plugin <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting vulnerability

CVSS:
7.1
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Mar 11, 2026

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.7. This is due to missing or incorrect nonce validation on the reload_preview() function. This makes it possible for unauthenticated attackers to...

CVSS:
6.1
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Mar 10, 2026

CVE-2026-2324 on NVD →

LatePoint - Authenticated (Agent+) Privilege Escalation vulnerability

high

Authenticated (Agent+) Privilege Escalation vulnerability

CVSS:
8.8
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Mar 5, 2026

LatePoint - Authenticated (Administrator+) SQL Injection via JSON Import vulnerability

high

Authenticated (Administrator+) SQL Injection via JSON Import vulnerability

CVSS:
7.6
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Mar 2, 2026

LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all versions up to, and including, 5.2.7 due to insufficient validation on the user-supplied JSON data. This makes it possible for authenticated attackers, with Administrator-l...

CVSS:
6.5
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Mar 2, 2026

CVE-2026-1487 on NVD →

LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set the 'wordpress_user_i...

CVSS:
8.8
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Mar 2, 2026

CVE-2026-1566 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.6

unknown

[en] The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verificat...

Affected:
up to 5.2.6
Fixed in:
5.2.6
Disclosed:
Feb 14, 2026

CVE-2025-14873 on NVD →

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verification....

CVSS:
4.3
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Feb 13, 2026

CVE-2025-14873 on NVD →

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_step() function in all versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to view booking informatio...

CVSS:
5.3
Affected:
up to 5.2.6
Fixed in:
5.2.7
Disclosed:
Feb 11, 2026

CVE-2026-1537 on NVD →

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting

high

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

CVSS:
7.2
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Feb 2, 2026

CVE-2026-0617 on NVD →

LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function

high

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce validation on the change_password() function of its customer_cabinet__change_password AJAX route. The plugin hooks this endpoint via wp_ajax and wp_ajax_nopriv but do...

CVSS:
8.8
Affected:
up to 5.1.94
Fixed in:
5.2.0
Disclosed:
Sep 29, 2025

CVE-2025-7052 on NVD →

LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function

high

The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in all versions up to, and including, 5.1.94. The endpoint reads the client-supplied customer email and related customer fields...

CVSS:
8.2
Affected:
up to 5.1.94
Fixed in:
5.2.0
Disclosed:
Sep 29, 2025

CVE-2025-7038 on NVD →

LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'latepoint_resources' shortcode in all versions up to, and including, 5.1.94 due to insufficient input sanitization and output escaping. This makes it possi...

CVSS:
6.4
Affected:
up to 5.1.94
Fixed in:
5.2.0
Disclosed:
Sep 29, 2025

CVE-2025-6941 on NVD →

LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘service[name]’ parameter in all versions up to, and including, 5.1.94 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

CVSS:
5.5
Affected:
up to 5.1.94
Fixed in:
5.2.0
Disclosed:
Sep 29, 2025

CVE-2025-6815 on NVD →

LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion

critical

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.93 via the 'layout' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing...

CVSS:
9.8
Affected:
up to 5.1.93
Fixed in:
5.1.94
Disclosed:
Jul 23, 2025

CVE-2025-6715 on NVD →

Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference

medium

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'view_booking_summary_in_lightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticate...

CVSS:
5.3
Affected:
up to 5.1.92
Fixed in:
5.1.93
Disclosed:
May 13, 2025

CVE-2025-3769 on NVD →

LatePoint <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 5.1.6
Fixed in:
5.1.7
Disclosed:
Mar 27, 2025

CVE-2025-30836 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.1.7

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LatePoint LatePoint allows Stored XSS. This issue affects LatePoint: from n/a through 5.1.6.

Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
Mar 27, 2025

CVE-2025-30836 on NVD →

LatePoint <= 5.0.12 - Authentication Bypass

critical

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such...

CVSS:
9.8
Affected:
up to 5.0.12
Fixed in:
5.0.13
Disclosed:
Sep 24, 2024

CVE-2024-8943 on NVD →

LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection

critical

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...

CVSS:
9.8
Affected:
up to 5.0.11
Fixed in:
5.0.12
Disclosed:
Sep 20, 2024

CVE-2024-8911 on NVD →

LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.91 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 4.9.91
Fix:
No patched version reported
Disclosed:
Aug 29, 2024

CVE-2024-43992 on NVD →

LatePoint <= 4.9.91 - Cross-Site Request Forgery

medium

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.91. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 4.9.91
Fix:
No patched version reported
Disclosed:
Aug 26, 2024

CVE-2024-43945 on NVD →

LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR

critical

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's c...

CVSS:
9.1
Affected:
up to 4.9.9
Fixed in:
4.9.9.1
Disclosed:
Jun 13, 2024

CVE-2024-2472 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.1.93

unknown
Affected:
up to 5.1.93
Fixed in:
5.1.93

CVE-2025-3769 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.1.94

unknown
Affected:
up to 5.1.94
Fixed in:
5.1.94

CVE-2025-6715 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0

unknown
Affected:
up to 5.2.0
Fixed in:
5.2.0

CVE-2025-6815 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0

unknown
Affected:
up to 5.2.0
Fixed in:
5.2.0

CVE-2025-6941 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0

unknown
Affected:
up to 5.2.0
Fixed in:
5.2.0

CVE-2025-7038 on NVD →

LatePoint &#8211; Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0

unknown
Affected:
up to 5.2.0
Fixed in:
5.2.0

CVE-2025-7052 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database