CVE Database /
CVE-2026-12657
CVE · Medium
CVE-2026-12657 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12657
|
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 |
Authorization Bypass Through User-Controlled Key |
Medium
5.3
|
< 5.6.3
|
5.6.3 |
2026-07-01 |
—
|
CVE-2026-12657
The LatePoint plugin for WordPress contains a flaw that allows attackers to manipulate bookings by exploiting an insecure reference to specific services. This vulnerability is present in all versions up to 5.6.2 and can be triggered through two parameters: 'service_id' in the params[booking][service_id] field or presets[selected_service]. As a result, unauthorized users can create approved bookings for restricted services, consuming available capacity and triggering unwanted bookings for admin-only services.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings