Impact
The LatePoint plugin for WordPress contains a blind SQL injection flaw that arises from improper neutralization of special elements in an SQL command. An attacker could exploit this vulnerability to read, modify, or delete data in the WordPress database, potentially exposing sensitive data or corrupting site.
Affected Systems
WordPress sites that use the LatePoint booking plugin version 5.6.3 or earlier are affected. The vulnerability up to and including 5.6.3.
Risk and Exploitability
The CVSS score of 9.3 indicates a severe impact. The EPSS score of <1% currently rare, but the vulnerability remains highly dangerous and is not listed in CISA KEV. The likely attack vector is via the plugin’s exposed HTTP endpoints, where a crafted query parameter may trigger the vulnerable SQL execution. The blind nature of the flaw means an attacker can infer data through timing or error responses. Administrators should treat this vulnerability with high urgency despite the low current exploitation probability.
OpenCVE Enrichment