Description
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-10-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthenticated SQL injection allowing data extraction
Action: Patch Immediately
AI Analysis

Impact

The LatePoint Appointment Booking Plugin accepts a user‑supplied 'booking[service_id]' parameter without proper escaping, enabling the execution of injected SQL commands. This flaw permits unauthenticated attackers to append arbitrary SQL statements to the existing database query, potentially leaking sensitive information from the WordPress database. The weakness is a classic SQL injection (CWE‑89), which threatens confidentiality of stored data.

Affected Systems

WordPress sites running the LatePoint plugin version 5.7.2 or older are affected. The vulnerability is present in all releases up to and including 5.7.2. Site owners should check their installed plugin version and upgrade if necessary.

Risk and Exploitability

With a CVSS score of 7.5 the flaw is considered high impact. No EPSS data is available, and it is not listed in the CISA KEV catalog, so the current exploitation likelihood is uncertain, but the lack of authentication makes this a likely vector. An attacker can craft an HTTP request containing a malicious value for 'booking[service_id]', causing the plugin to execute unintended SQL on the database server and read or modify data.

Generated by OpenCVE AI on October 10, 2026 at 09:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LatePoint to a version newer than 5.7.2 or apply the official vendor patch if available
  • If an immediate upgrade is not possible, block or heavily filter requests to the booking endpoint, using a web application firewall rule that blocks SQL injection patterns
  • Restrict the database user privileges used by WordPress, ensuring it has only the permissions strictly required by the application

Generated by OpenCVE AI on October 10, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_id]' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:43.527Z

Reserved: 2026-09-23T14:51:55.113Z

Link: CVE-2026-96662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:08.033

Modified: 2026-10-10T08:17:08.033

Link: CVE-2026-96662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')