CVE Database /
CVE-2026-5234
CVE · Medium
CVE-2026-5234 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-5234
|
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 |
Authorization Bypass Through User-Controlled Key |
Medium
5.3
|
< 5.4.0
|
5.4.0 |
2026-04-16 |
—
|
CVE-2026-5234
The LatePoint plugin for WordPress has a flaw in its handling of invoices that allows unauthorized access to sensitive financial data. In versions up to 5.3.2, an attacker can exploit this vulnerability by accessing public actions without authentication, which enables them to enumerate valid invoice IDs and create unauthorized transaction intent records containing customer information and payment amounts. This also results in the disclosure of Stripe payment tokens and other related details on sites with Stripe Connect enabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings