Impact
This vulnerability is a stored Cross‑Site Scripting flaw that originates from customer profile fields in the LatePoint plugin. Unauthenticated users can insert malicious scripts that are saved and later executed whenever an administrator opens the activity history page. Because the payload runs in the context of the administrator’s session, an attacker could hijack credentials, perform phishing, or execute further attacks against the site.
Affected Systems
WordPress sites that use the LatePoint – Calendar Booking Plugin for Appointments and Events, version 5.2.5 or earlier.
Risk and Exploitability
The CVSS base score of 7.2 classifies it as high severity, yet the EPSS score below 1% suggests a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack path requires no authentication; any visitor can supply input that will later be rendered for an administrator, making the flaw readily exploitable if the plugin is not patched.
OpenCVE Enrichment