CVE

CVE-2026-15250 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15250 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.8 Improper Access Control Unknown < 5.6.8 5.6.8 2026-07-30

CVE-2026-15250

An unverified website visitor can manipulate certain booking settings on the Appointment Booking Plugin for WordPress prior to version 5.6.8 by exploiting a lack of access controls in its public booking interface, potentially allowing them to alter sensitive field values like approval status and circumvent the site's review process. This vulnerability arises from insufficient restrictions on which fields are editable through the plugin's public booking funnel.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.