CVE · Medium

CVE-2025-14873 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14873 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6 Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.2.6 5.2.6 2026-02-13

CVE-2025-14873

The LatePoint plugin for WordPress, used for scheduling appointments and events, has a security weakness in its routing system that affects all versions up to 5.2.5. Specifically, the 'call_by_route_name' function doesn't properly check whether a request is legitimate or not, allowing an attacker to execute administrative tasks without needing authentication. This vulnerability can be exploited if a site administrator clicks on a malicious link, enabling the attacker to carry out multiple unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.