CVE · Medium

CVE-2026-5234 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5234 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 Authorization Bypass Through User-Controlled Key Medium 5.3 < 5.4.0 5.4.0 2026-04-16

CVE-2026-5234

The LatePoint plugin for WordPress has a flaw in its handling of invoices that allows unauthorized access to sensitive financial data. In versions up to 5.3.2, an attacker can exploit this vulnerability by accessing public actions without authentication, which enables them to enumerate valid invoice IDs and create unauthorized transaction intent records containing customer information and payment amounts. This also results in the disclosure of Stripe payment tokens and other related details on sites with Stripe Connect enabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.