PLUGIN SECURITY

Is Latepoint safe?

Appointment booking plugin for WordPress. Let clients self-schedule 24/7, accept payments at booking, and reduce no-shows, all from your WordPress sit …

What this plugin does

  • Slug: latepoint
  • Author: LatePoint
  • 100000+ active installs
  • 98/100 rating (98 reviews on wordpress.org)
  • 1481625 all-time downloads
  • On WordPress.org since 2025-01-29

appointment bookingappointmentsbookingbooking systemscheduling

Maintenance status

  • Latest known version: 5.6.10
  • Last updated: 2026-08-02 4:13am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

36 known CVEs on file for Latepoint.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5391 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.4.0 5.4.0 2026-08-05 ✓ fixed in latest
CVE-2026-15250 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.8 Improper Access Control Unknown < 5.6.8 5.6.8 2026-07-30 ✓ fixed in latest
CVE-2026-57714 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4 Critical 9.3 < 5.6.4 5.6.4 2026-07-08 ✓ fixed in latest
CVE-2026-5356 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.1 Missing Authorization High 7.5 < 5.4.1 5.4.1 2026-07-07 ✓ fixed in latest
CVE-2026-11398 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.2 Missing Authorization Medium 5.3 < 5.6.2 5.6.2 2026-07-02 ✓ fixed in latest
CVE-2026-12657 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 Authorization Bypass Through User-Controlled Key Medium 5.3 < 5.6.3 5.6.3 2026-07-01 ✓ fixed in latest
CVE-2026-13228 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4 Improper Privilege Management High 8.8 < 5.6.4 5.6.4 2026-06-30 ✓ fixed in latest
CVE-2026-11866 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3 Cross-Site Request Forgery (CSRF) Unknown < 5.6.3 5.6.3 2026-06-25 ✓ fixed in latest
+ 43 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8176 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2 Improper Privilege Management High 7.5 < 5.5.2 5.5.2 2026-06-15 ✓ fixed in latest
CVE-2026-9719 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.1 Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.6.1 5.6.1 2026-06-05 ✓ fixed in latest
CVE-2026-49083 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2 Incorrect Privilege Assignment High 7.5 < 5.5.2 5.5.2 2026-06-05 ✓ fixed in latest
CVE-2026-5365 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.4.0 5.4.0 2026-05-13 ✓ fixed in latest
CVE-2026-7652 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 Weak Password Recovery Mechanism for Forgotten Password Medium 5.3 < 5.5.1 5.5.1 2026-05-08 ✓ fixed in latest
CVE-2026-7332 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 5.5.1 5.5.1 2026-05-05 ✓ fixed in latest
CVE-2026-7448 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.5.1 5.5.1 2026-05-05 ✓ fixed in latest
CVE-2026-7457 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.5.1 5.5.1 2026-05-05 ✓ fixed in latest
CVE-2026-6741 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.2 Improper Privilege Management High 8.8 < 5.4.2 5.4.2 2026-04-27 ✓ fixed in latest
CVE-2026-5234 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0 Authorization Bypass Through User-Controlled Key Medium 5.3 < 5.4.0 5.4.0 2026-04-16 ✓ fixed in latest
CVE-2026-32533 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.7 Authorization Bypass Through User-Controlled Key Medium 6.5 < 5.2.7 5.2.7 2026-03-23 ✓ fixed in latest
CVE-2025-14873 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6 Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.2.6 5.2.6 2026-02-13 ✓ fixed in latest
CVE-2025-30836 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 5.1.7 5.1.7 2025-03-27 ✓ fixed in latest
CVE-2024-8943 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.0.13 Authentication Bypass Using an Alternate Path or Channel Critical 9.8 < 5.0.13 5.0.13 2024-09-24 ✓ fixed in latest
CVE-2024-8911 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.0.12 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 5.0.12 5.0.12 2024-09-20 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] <= 4.9.91 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.9.91 4.9.91 2024-08-29 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] <= 4.9.91 (unfixed) Cross-Site Request Forgery (CSRF) High 8.8 < 4.9.91 4.9.91 2024-08-26 ✓ fixed in latest
CVE-2024-2472 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 4.9.9.1 Authorization Bypass Through User-Controlled Key Critical 9.1 < 4.9.9.1 4.9.9.1 2024-06-13 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.93 Authorization Bypass Through User-Controlled Key Medium 5.3 < 5.1.93 5.1.93 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.94 Critical 9.8 < 5.1.94 5.1.94 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.5 < 5.2.0 5.2.0 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.2.0 5.2.0 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 Authentication Bypass Using an Alternate Path or Channel High 8.2 < 5.2.0 5.2.0 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.0 Cross-Site Request Forgery (CSRF) High 8.8 < 5.2.0 5.2.0 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.3.1 Unknown < 5.3.1 5.3.1 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.8 Unknown < 5.2.8 5.2.8 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.8 Unknown < 5.2.8 5.2.8 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.8 Unknown < 5.2.8 5.2.8 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.7 Unknown < 5.2.7 5.2.7 0000-00-00 ✓ fixed in latest
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6 Unknown < 5.2.6 5.2.6 0000-00-00 ✓ fixed in latest
CVE-2025-3769 Latepoint < 5.1.93 - Unauthenticated Insecure Direct Object Reference Unknown < 5.1.93 5.1.93 ✓ fixed in latest
CVE-2025-6715 Latepoint < 5.1.94 - Unauthenticated LFI Unknown < 5.1.94 5.1.94 ✓ fixed in latest
CVE-2025-6941 LatePoint < 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Unknown < 5.2.0 5.2.0 ✓ fixed in latest
CVE-2025-6815 LatePoint < 5.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting Unknown < 5.2.0 5.2.0 ✓ fixed in latest
CVE-2025-7052 LatePoint < 5.2.0 - Account Takeover via CSRF Unknown < 5.2.0 5.2.0 ✓ fixed in latest
CVE-2025-7038 LatePoint < 5.2.0 - Unauthenticated Authentication Bypass Unknown < 5.2.0 5.2.0 ✓ fixed in latest
CVE-2026-0617 LatePoint < 5.2.6 - Unauthenticated Stored XSS Unknown < 5.2.6 5.2.6 ✓ fixed in latest
CVE-2026-1537 LatePoint – Calendar Booking Plugin for Appointments and Events < 5.2.7 - Missing Authorization to Booking Details Exposure Unknown < 5.2.7 5.2.7 ✓ fixed in latest
CVE-2026-1487 LatePoint < 5.2.8 - Authenticated (Administrator+) SQL Injection via JSON Import Unknown < 5.2.8 5.2.8 ✓ fixed in latest
CVE-2026-1566 LatePoint < 5.2.8 - Agent+ Privilege Escalation Unknown < 5.2.8 5.2.8 ✓ fixed in latest
CVE-2026-2324 LatePoint – Calendar Booking Plugin for Appointments and Events < 5.2.8 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting Unknown < 5.2.8 5.2.8 ✓ fixed in latest
CVE-2026-4785 LatePoint < 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Unknown < 5.3.1 5.3.1 ✓ fixed in latest
CVE-2026-6741 LatePoint < 5.4.2 - Agent+ Privilege Escalation Unknown < 5.4.2 5.4.2 ✓ fixed in latest

How to fix it

Keep Latepoint updated — 5.6.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.