CVE Database /
CVE-2026-11866
CVE
CVE-2026-11866 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-11866
|
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 |
Cross-Site Request Forgery (CSRF) |
Unknown
|
< 5.6.3
|
5.6.3 |
2026-06-25 |
—
|
CVE-2026-11866
The LatePoint plugin for WordPress contains a security flaw that allows malicious actors to manipulate administrative actions without proper authorization in versions prior to 5.6.2, due to inadequate validation of certain requests. This vulnerability enables attackers to deceive administrators into executing unintended actions by exploiting the lack of nonce verification on specific functions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings