Impact
The LatePoint WordPress plugin is affected by a stored cross‑site scripting flaw that occurs when the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode is not properly sanitized. An attacker who can log in to the site with contributor or higher privileges can embed malicious scripts into this attribute. When any user views a page containing the injected shortcode, the script executes in that user’s browser.
Affected Systems
This vulnerability is present in all versions of the LatePoint Appointment Booking Plugin up to and including 5.3.2. Users running these versions on WordPress sites are at risk.
Risk and Exploitability
With a CVSS score of 6.4, the flaw represents moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires authenticated access at the contributor level or higher, but once achieved, the payload runs automatically for any visitor who accesses the affected page. No specific software configuration or network access prerequisites are noted beyond the existing permissions.
OpenCVE Enrichment