Description
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verification. This makes it possible for unauthenticated attackers to perform multiple administrative actions via forged requests granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2026-02-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery enables unauthenticated users to trigger privileged administrative actions within LatePoint
Action: Patch
AI Analysis

Impact

The flaw resides in LatePoint’s routing layer where the call_by_route_name function verifies only user capabilities without requiring a nonce. This oversight allows any visitor to fabricate forged requests that, when executed by an authenticated administrator, can carry out any administrative operation such as creating, modifying or deleting bookings, changing plugin settings, or accessing sensitive data. Because no authentication is needed to craft the request, the vulnerability effectively provides a conduit for unauthenticated attackers to perform any action an administrator can perform.

Affected Systems

All releases of the LatePoint – Calendar Booking Plugin for Appointments and Events up to and including version 5.2.5 are affected. The plugin is distributed under the vendor name LatePoint and operates as a WordPress extension for managing events and bookings.

Risk and Exploitability

The CVSS score of 4.3 places the issue in the moderate severity range, yet the EPSS score of less than 1% indicates a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. The attack vector is typical of CSRF: a malicious link or payload that forces a logged‑in administrator to perform an unintended action. Successful exploitation would require the administrator to be authenticated and could be achieved through social engineering or embedded content. Overall, the risk is moderate, recommending prompt action for any site that permits administrator‑level operations through LatePoint.

Generated by OpenCVE AI on April 22, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LatePoint to a version newer than 5.2.5 that implements nonce verification for the routing layer
  • Restrict administrative capabilities by tightening role permissions so that only trusted users can execute high‑privilege actions
  • Apply an additional CSRF defense, such as a site‑wide security plugin that blocks anonymous POST requests to admin endpoints or enforces a global nonce on all admin actions

Generated by OpenCVE AI on April 22, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Latepoint
Latepoint latepoint – Calendar Booking Plugin For Appointments And Events
Wordpress
Wordpress wordpress
Vendors & Products Latepoint
Latepoint latepoint – Calendar Booking Plugin For Appointments And Events
Wordpress
Wordpress wordpress

Sat, 14 Feb 2026 06:45:00 +0000

Type Values Removed Values Added
Description The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verification. This makes it possible for unauthenticated attackers to perform multiple administrative actions via forged requests granted they can trick a site administrator into performing an action such as clicking on a link.
Title LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Latepoint Latepoint – Calendar Booking Plugin For Appointments And Events
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:41:01.219Z

Reserved: 2025-12-18T06:12:42.314Z

Link: CVE-2025-14873

cve-icon Vulnrichment

Updated: 2026-02-17T15:36:50.774Z

cve-icon NVD

Status : Deferred

Published: 2026-02-14T07:16:06.887

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T15:30:20Z

Weaknesses