Impact
The LatePoint Appointment Booking Plugin accepts a user‑supplied 'booking[service_id]' parameter without proper escaping, enabling the execution of injected SQL commands. This flaw permits unauthenticated attackers to append arbitrary SQL statements to the existing database query, potentially leaking sensitive information from the WordPress database. The weakness is a classic SQL injection (CWE‑89), which threatens confidentiality of stored data.
Affected Systems
WordPress sites running the LatePoint plugin version 5.7.2 or older are affected. The vulnerability is present in all releases up to and including 5.7.2. Site owners should check their installed plugin version and upgrade if necessary.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is considered high impact. No EPSS data is available, and it is not listed in the CISA KEV catalog, so the current exploitation likelihood is uncertain, but the lack of authentication makes this a likely vector. An attacker can craft an HTTP request containing a malicious value for 'booking[service_id]', causing the plugin to execute unintended SQL on the database server and read or modify data.
OpenCVE Enrichment