Impact
Authenticated administrators with access to the LatePoint JSON import feature can supply malformed JSON that bypasses server‑side validation. The plugin’s input sanitization flaw allows an attacker to inject arbitrary SQL statements, enabling the execution of time‑based queries, data extraction, table deletion, or data alteration. The impact is a compromise of database confidentiality, integrity, and availability within the WordPress site, limited to users with at least administrator privileges.
Affected Systems
LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress, versions 5.2.7 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is less than 1 % suggesting a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated administrator using the JSON import interface; no external access or elevated privileges beyond the administrator role are required, and no public exploit has been reported in the provided references.
OpenCVE Enrichment