CVE

CVE-2026-11866 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11866 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 Cross-Site Request Forgery (CSRF) Unknown < 5.6.3 5.6.3 2026-06-25

CVE-2026-11866

The LatePoint plugin for WordPress contains a security flaw that allows malicious actors to manipulate administrative actions without proper authorization in versions prior to 5.6.2, due to inadequate validation of certain requests. This vulnerability enables attackers to deceive administrators into executing unintended actions by exploiting the lack of nonce verification on specific functions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.