CVE · Medium

CVE-2026-12657 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12657 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 Authorization Bypass Through User-Controlled Key Medium 5.3 < 5.6.3 5.6.3 2026-07-01

CVE-2026-12657

The LatePoint plugin for WordPress contains a flaw that allows attackers to manipulate bookings by exploiting an insecure reference to specific services. This vulnerability is present in all versions up to 5.6.2 and can be triggered through two parameters: 'service_id' in the params[booking][service_id] field or presets[selected_service]. As a result, unauthorized users can create approved bookings for restricted services, consuming available capacity and triggering unwanted bookings for admin-only services.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.