LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the 'locations' branch of the 'shortcode_latep...
- CVSS:
- 6.4
- Affected:
- up to 5.3.2
- Fixed in:
- 5.4.0
- Disclosed:
- Aug 5, 2026
CVE-2026-5391 on NVD →
LatePoint <= 5.6.7 - Missing Authorization to Unauthenticated Booking Object Mass Assignment
medium
The LatePoint plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.6.7. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.6.7
- Fixed in:
- 5.6.8
- Disclosed:
- Jul 10, 2026
CVE-2026-15250 on NVD →
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.3 - Unauthenticated SQL Injection
high
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...
- CVSS:
- 7.5
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Jul 8, 2026
CVE-2026-57714 on NVD →
LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. This makes it possible for unauthent...
- CVSS:
- 7.5
- Affected:
- up to 5.4.0
- Fixed in:
- 5.4.1
- Disclosed:
- Jul 7, 2026
CVE-2026-5356 on NVD →
LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attacker...
- CVSS:
- 5.3
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Jul 2, 2026
CVE-2026-11398 on NVD →
LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers t...
- CVSS:
- 5.3
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Jul 1, 2026
CVE-2026-12657 on NVD →
LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.6.3 This is due to an Insecure Direct Object Reference (IDOR) in the create_or_update() function of OsOrdersController, which allows an auth...
- CVSS:
- 8.8
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Jun 30, 2026
CVE-2026-13228 on NVD →
LatePoint <= 5.6.2 - Cross-Site Request Forgery
medium
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Jun 25, 2026
CVE-2026-11866 on NVD →
LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's...
- CVSS:
- 7.5
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.2
- Disclosed:
- Jun 15, 2026
CVE-2026-8176 on NVD →
LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the change_status function. This makes it possible for unauthenticated attackers to ch...
- CVSS:
- 4.3
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.1
- Disclosed:
- Jun 5, 2026
CVE-2026-9719 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege Escalation
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to elevate their privileges to that of an administrator...
- CVSS:
- 8.8
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.2
- Disclosed:
- Jun 5, 2026
CVE-2026-49083 on NVD →
LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route
medium
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() function. This makes it possible for unauthenticated attackers to cancel a logged-in customer's bookings via a forged request,...
- CVSS:
- 4.3
- Affected:
- up to 5.3.2
- Fixed in:
- 5.4.0
- Disclosed:
- May 13, 2026
CVE-2026-5365 on NVD →
LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism
medium
The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due to the save_connected_wordpress_user() function propagating a LatePoint customer's email address to its linked WordPress...
- CVSS:
- 5.3
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- May 8, 2026
CVE-2026-7652 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- CVSS:
- 7.2
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- May 6, 2026
CVE-2026-7448 on NVD →
LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 7.2
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- May 5, 2026
CVE-2026-7332 on NVD →
LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update
medium
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input sanitization on the customer cabinet profile update endpoint — where raw POST parameters (first_name, last_name, phone, notes) bypass sanitization because OsCustom...
- CVSS:
- 6.4
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- May 5, 2026
CVE-2026-7457 on NVD →
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires the customer__edit ca...
- CVSS:
- 8.8
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- Apr 27, 2026
CVE-2026-6741 on NVD →
LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
medium
The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no authentication required) and loads invoices...
- CVSS:
- 5.3
- Affected:
- up to 5.3.2
- Fixed in:
- 5.4.0
- Disclosed:
- Apr 16, 2026
CVE-2026-5234 on NVD →
LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping when the 'items' parameter is...
- CVSS:
- 6.4
- Affected:
- up to 5.3.0
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 7, 2026
CVE-2026-4785 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.2.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 4.3
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- Mar 23, 2026
CVE-2026-32533 on NVD →
LatePoint - WordPress LatePoint - Calendar Booking Plugin for Appointments and Events plugin <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting vulnerability
high
WordPress LatePoint - Calendar Booking Plugin for Appointments and Events plugin <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting vulnerability
- CVSS:
- 7.1
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Mar 11, 2026
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.7. This is due to missing or incorrect nonce validation on the reload_preview() function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Mar 10, 2026
CVE-2026-2324 on NVD →
LatePoint - Authenticated (Agent+) Privilege Escalation vulnerability
high
Authenticated (Agent+) Privilege Escalation vulnerability
- CVSS:
- 8.8
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Mar 5, 2026
LatePoint - Authenticated (Administrator+) SQL Injection via JSON Import vulnerability
high
Authenticated (Administrator+) SQL Injection via JSON Import vulnerability
- CVSS:
- 7.6
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Mar 2, 2026
LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all versions up to, and including, 5.2.7 due to insufficient validation on the user-supplied JSON data. This makes it possible for authenticated attackers, with Administrator-l...
- CVSS:
- 6.5
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Mar 2, 2026
CVE-2026-1487 on NVD →
LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set the 'wordpress_user_i...
- CVSS:
- 8.8
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Mar 2, 2026
CVE-2026-1566 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.6
unknown
[en] The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verificat...
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.6
- Disclosed:
- Feb 14, 2026
CVE-2025-14873 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verification....
- CVSS:
- 4.3
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Feb 13, 2026
CVE-2025-14873 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_step() function in all versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to view booking informatio...
- CVSS:
- 5.3
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- Feb 11, 2026
CVE-2026-1537 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting
high
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- CVSS:
- 7.2
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Feb 2, 2026
CVE-2026-0617 on NVD →
LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function
high
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce validation on the change_password() function of its customer_cabinet__change_password AJAX route. The plugin hooks this endpoint via wp_ajax and wp_ajax_nopriv but do...
- CVSS:
- 8.8
- Affected:
- up to 5.1.94
- Fixed in:
- 5.2.0
- Disclosed:
- Sep 29, 2025
CVE-2025-7052 on NVD →
LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function
high
The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in all versions up to, and including, 5.1.94. The endpoint reads the client-supplied customer email and related customer fields...
- CVSS:
- 8.2
- Affected:
- up to 5.1.94
- Fixed in:
- 5.2.0
- Disclosed:
- Sep 29, 2025
CVE-2025-7038 on NVD →
LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'latepoint_resources' shortcode in all versions up to, and including, 5.1.94 due to insufficient input sanitization and output escaping. This makes it possi...
- CVSS:
- 6.4
- Affected:
- up to 5.1.94
- Fixed in:
- 5.2.0
- Disclosed:
- Sep 29, 2025
CVE-2025-6941 on NVD →
LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘service[name]’ parameter in all versions up to, and including, 5.1.94 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 5.5
- Affected:
- up to 5.1.94
- Fixed in:
- 5.2.0
- Disclosed:
- Sep 29, 2025
CVE-2025-6815 on NVD →
LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion
critical
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.93 via the 'layout' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing...
- CVSS:
- 9.8
- Affected:
- up to 5.1.93
- Fixed in:
- 5.1.94
- Disclosed:
- Jul 23, 2025
CVE-2025-6715 on NVD →
Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference
medium
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'view_booking_summary_in_lightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticate...
- CVSS:
- 5.3
- Affected:
- up to 5.1.92
- Fixed in:
- 5.1.93
- Disclosed:
- May 13, 2025
CVE-2025-3769 on NVD →
LatePoint <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 5.1.6
- Fixed in:
- 5.1.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30836 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.1.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LatePoint LatePoint allows Stored XSS. This issue affects LatePoint: from n/a through 5.1.6.
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30836 on NVD →
LatePoint <= 5.0.12 - Authentication Bypass
critical
The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such...
- CVSS:
- 9.8
- Affected:
- up to 5.0.12
- Fixed in:
- 5.0.13
- Disclosed:
- Sep 24, 2024
CVE-2024-8943 on NVD →
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
critical
The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...
- CVSS:
- 9.8
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.12
- Disclosed:
- Sep 20, 2024
CVE-2024-8911 on NVD →
LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.91 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 4.9.91
- Fix:
- No patched version reported
- Disclosed:
- Aug 29, 2024
CVE-2024-43992 on NVD →
LatePoint <= 4.9.91 - Cross-Site Request Forgery
medium
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.91. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 4.9.91
- Fix:
- No patched version reported
- Disclosed:
- Aug 26, 2024
CVE-2024-43945 on NVD →
LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR
critical
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's c...
- CVSS:
- 9.1
- Affected:
- up to 4.9.9
- Fixed in:
- 4.9.9.1
- Disclosed:
- Jun 13, 2024
CVE-2024-2472 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.1.93
unknown
- Affected:
- up to 5.1.93
- Fixed in:
- 5.1.93
CVE-2025-3769 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.1.94
unknown
- Affected:
- up to 5.1.94
- Fixed in:
- 5.1.94
CVE-2025-6715 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0
unknown
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
CVE-2025-6815 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0
unknown
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
CVE-2025-6941 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0
unknown
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
CVE-2025-7038 on NVD →
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] < 5.2.0
unknown
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
CVE-2025-7052 on NVD →