Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3.
Published: 2026-07-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LatePoint plugin for WordPress contains a blind SQL injection flaw that arises from improper neutralization of special elements in an SQL command. An attacker could exploit this vulnerability to read, modify, or delete data in the WordPress database, potentially exposing sensitive data or corrupting site.

Affected Systems

WordPress sites that use the LatePoint booking plugin version 5.6.3 or earlier are affected. The vulnerability up to and including 5.6.3.

Risk and Exploitability

The CVSS score of 9.3 indicates a severe impact. The EPSS score of <1% currently rare, but the vulnerability remains highly dangerous and is not listed in CISA KEV. The likely attack vector is via the plugin’s exposed HTTP endpoints, where a crafted query parameter may trigger the vulnerable SQL execution. The blind nature of the flaw means an attacker can infer data through timing or error responses. Administrators should treat this vulnerability with high urgency despite the low current exploitation probability.

Generated by OpenCVE AI on August 1, 2026 at 10:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LatePoint to version 5.6.4 or later to patch the SQL injection flaw.
  • Restrict access to the plugin’s administrative pages and enforce strict database user privileges, limiting the plugin to only the permissions required for normal site operation.
  • Disable the LatePoint plugin via the WordPress admin panel until the patch is applied.
  • If the booking functionality can be replaced, uninstall the LatePoint plugin entirely to eliminate the attack surface.

Generated by OpenCVE AI on August 1, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Latepoint
Latepoint latepoint
Wordpress
Wordpress wordpress
Vendors & Products Latepoint
Latepoint latepoint
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3.
Title WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Latepoint Latepoint
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:30:52.769Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57714

cve-icon Vulnrichment

Updated: 2026-07-13T13:30:50.005Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')