PLUGIN SECURITY
Is Latepoint safe?
Appointment booking plugin for WordPress. Let clients self-schedule 24/7, accept payments at booking, and reduce no-shows, all from your WordPress sit …
What this plugin does
- Slug:
latepoint - Author: LatePoint
- 100000+ active installs
- 98/100 rating (98 reviews on wordpress.org)
- 1481625 all-time downloads
- On WordPress.org since 2025-01-29
appointment bookingappointmentsbookingbooking systemscheduling
Maintenance status
- Latest known version: 5.6.10
- Last updated: 2026-08-02 4:13am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
36 known CVEs on file for Latepoint.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-5391 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.4.0 | 5.4.0 | 2026-08-05 | ✓ fixed in latest |
| CVE-2026-15250 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.8 | Improper Access Control | Unknown | < 5.6.8 | 5.6.8 | 2026-07-30 | ✓ fixed in latest |
| CVE-2026-57714 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4 | — | Critical 9.3 | < 5.6.4 | 5.6.4 | 2026-07-08 | ✓ fixed in latest |
| CVE-2026-5356 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.1 | Missing Authorization | High 7.5 | < 5.4.1 | 5.4.1 | 2026-07-07 | ✓ fixed in latest |
| CVE-2026-11398 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.2 | Missing Authorization | Medium 5.3 | < 5.6.2 | 5.6.2 | 2026-07-02 | ✓ fixed in latest |
| CVE-2026-12657 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 5.6.3 | 5.6.3 | 2026-07-01 | ✓ fixed in latest |
| CVE-2026-13228 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4 | Improper Privilege Management | High 8.8 | < 5.6.4 | 5.6.4 | 2026-06-30 | ✓ fixed in latest |
| CVE-2026-11866 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 | Cross-Site Request Forgery (CSRF) | Unknown | < 5.6.3 | 5.6.3 | 2026-06-25 | ✓ fixed in latest |
+ 43 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-8176 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2 | Improper Privilege Management | High 7.5 | < 5.5.2 | 5.5.2 | 2026-06-15 | ✓ fixed in latest |
| CVE-2026-9719 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.1 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 5.6.1 | 5.6.1 | 2026-06-05 | ✓ fixed in latest |
| CVE-2026-49083 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2 | Incorrect Privilege Assignment | High 7.5 | < 5.5.2 | 5.5.2 | 2026-06-05 | ✓ fixed in latest |
| CVE-2026-5365 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 5.4.0 | 5.4.0 | 2026-05-13 | ✓ fixed in latest |
| CVE-2026-7652 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 | Weak Password Recovery Mechanism for Forgotten Password | Medium 5.3 | < 5.5.1 | 5.5.1 | 2026-05-08 | ✓ fixed in latest |
| CVE-2026-7332 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 5.5.1 | 5.5.1 | 2026-05-05 | ✓ fixed in latest |
| CVE-2026-7448 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 5.5.1 | 5.5.1 | 2026-05-05 | ✓ fixed in latest |
| CVE-2026-7457 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.5.1 | 5.5.1 | 2026-05-05 | ✓ fixed in latest |
| CVE-2026-6741 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2 | Improper Privilege Management | High 8.8 | < 5.4.2 | 5.4.2 | 2026-04-27 | ✓ fixed in latest |
| CVE-2026-5234 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 5.4.0 | 5.4.0 | 2026-04-16 | ✓ fixed in latest |
| CVE-2026-32533 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.7 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 5.2.7 | 5.2.7 | 2026-03-23 | ✓ fixed in latest |
| CVE-2025-14873 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 5.2.6 | 5.2.6 | 2026-02-13 | ✓ fixed in latest |
| CVE-2025-30836 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.1.7 | 5.1.7 | 2025-03-27 | ✓ fixed in latest |
| CVE-2024-8943 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.0.13 | Authentication Bypass Using an Alternate Path or Channel | Critical 9.8 | < 5.0.13 | 5.0.13 | 2024-09-24 | ✓ fixed in latest |
| CVE-2024-8911 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.0.12 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 5.0.12 | 5.0.12 | 2024-09-20 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] <= 4.9.91 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.9.91 | 4.9.91 | 2024-08-29 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] <= 4.9.91 (unfixed) | Cross-Site Request Forgery (CSRF) | High 8.8 | < 4.9.91 | 4.9.91 | 2024-08-26 | ✓ fixed in latest |
| CVE-2024-2472 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 4.9.9.1 | Authorization Bypass Through User-Controlled Key | Critical 9.1 | < 4.9.9.1 | 4.9.9.1 | 2024-06-13 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.93 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 5.1.93 | 5.1.93 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.94 | — | Critical 9.8 | < 5.1.94 | 5.1.94 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.5 | < 5.2.0 | 5.2.0 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.2.0 | 5.2.0 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 | Authentication Bypass Using an Alternate Path or Channel | High 8.2 | < 5.2.0 | 5.2.0 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 5.2.0 | 5.2.0 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.3.1 | — | Unknown | < 5.3.1 | 5.3.1 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.8 | — | Unknown | < 5.2.8 | 5.2.8 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.8 | — | Unknown | < 5.2.8 | 5.2.8 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.8 | — | Unknown | < 5.2.8 | 5.2.8 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.7 | — | Unknown | < 5.2.7 | 5.2.7 | 0000-00-00 | ✓ fixed in latest |
| — | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6 | — | Unknown | < 5.2.6 | 5.2.6 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-3769 | Latepoint < 5.1.93 - Unauthenticated Insecure Direct Object Reference | — | Unknown | < 5.1.93 | 5.1.93 | — | ✓ fixed in latest |
| CVE-2025-6715 | Latepoint < 5.1.94 - Unauthenticated LFI | — | Unknown | < 5.1.94 | 5.1.94 | — | ✓ fixed in latest |
| CVE-2025-6941 | LatePoint < 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | — | Unknown | < 5.2.0 | 5.2.0 | — | ✓ fixed in latest |
| CVE-2025-6815 | LatePoint < 5.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting | — | Unknown | < 5.2.0 | 5.2.0 | — | ✓ fixed in latest |
| CVE-2025-7052 | LatePoint < 5.2.0 - Account Takeover via CSRF | — | Unknown | < 5.2.0 | 5.2.0 | — | ✓ fixed in latest |
| CVE-2025-7038 | LatePoint < 5.2.0 - Unauthenticated Authentication Bypass | — | Unknown | < 5.2.0 | 5.2.0 | — | ✓ fixed in latest |
| CVE-2026-0617 | LatePoint < 5.2.6 - Unauthenticated Stored XSS | — | Unknown | < 5.2.6 | 5.2.6 | — | ✓ fixed in latest |
| CVE-2026-1537 | LatePoint – Calendar Booking Plugin for Appointments and Events < 5.2.7 - Missing Authorization to Booking Details Exposure | — | Unknown | < 5.2.7 | 5.2.7 | — | ✓ fixed in latest |
| CVE-2026-1487 | LatePoint < 5.2.8 - Authenticated (Administrator+) SQL Injection via JSON Import | — | Unknown | < 5.2.8 | 5.2.8 | — | ✓ fixed in latest |
| CVE-2026-1566 | LatePoint < 5.2.8 - Agent+ Privilege Escalation | — | Unknown | < 5.2.8 | 5.2.8 | — | ✓ fixed in latest |
| CVE-2026-2324 | LatePoint – Calendar Booking Plugin for Appointments and Events < 5.2.8 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting | — | Unknown | < 5.2.8 | 5.2.8 | — | ✓ fixed in latest |
| CVE-2026-4785 | LatePoint < 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | — | Unknown | < 5.3.1 | 5.3.1 | — | ✓ fixed in latest |
| CVE-2026-6741 | LatePoint < 5.4.2 - Agent+ Privilege Escalation | — | Unknown | < 5.4.2 | 5.4.2 | — | ✓ fixed in latest |
How to fix it
Keep Latepoint updated — 5.6.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Booking for Appointments and Events Calendar – Amelia — 90000+ active installs — 92/100 (784)
- Online Scheduling and Appointment Booking System – Bookly — 60000+ active installs — 88/100 (575) — max PHP <8.0
- Simply Schedule Appointments — 50000+ active installs — 100/100 (155) — max PHP 8.4
- Booking Calendar — 40000+ active installs — 94/100 (653) — max PHP 8.4
- SimplyBook.me – Booking and reservations calendar — 30000+ active installs — 90/100 (17) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.