LatePoint, a WordPress appointment booking plugin running on more than 100,000 service-business sites, has patched a critical vulnerability that let unauthenticated attackers inject and run arbitrary shortcodes through its public booking form. Tracked as CVE-2026-92966 and rated 9.1 (critical) on the CVSS scale, the flaw affects every version up to and including 5.7.0. LatePoint fixed it quietly in version 5.7.1, released September 25, 2026, after Wordfence reported the issue, and the CVE itself went public on October 1. If a site is still running 5.7.0 or older, this is worth checking today.
How the Flaw Actually Works
The bug sits in how LatePoint renders a customer’s name inside its Customer Cabinet dashboard. Anyone can submit a booking without an account, and the plugin never validated what landed in the name field before storing it. Plant a WordPress shortcode there instead of a real name, and once that booking shows up in the customer dashboard, WordPress’s own do_shortcode filter parses and runs it. No login, no admin tricked into clicking anything, nothing beyond filling out a public form.
Wordfence and NVD classify this as CWE-94, code injection. The actual damage a shortcode can do depends on what else is installed. Some page builders and utility plugins expose shortcodes that touch files, templates, or server-side logic well beyond basic formatting, so the real blast radius varies site to site, which is part of why this scored a 9.1 instead of something more contained.
Who Should Act, and What to Check
Any site taking bookings through LatePoint, salons, clinics, tutors, consultants, fitness studios, is exposed if it hasn’t updated past 5.7.0. A few concrete steps:
- Update LatePoint to version 5.7.1 or later now, before anything else.
- Scan recent booking entries for odd content in name or customer fields, especially anything wrapped in square brackets.
- Check which other active plugins register shortcodes with real side effects (file operations, template includes, settings changes), since those are what turn this bug from annoying into dangerous.
- If a suspicious booking predates the patch and an admin has logged in since, rotate credentials and review the user list for accounts that shouldn’t be there.
The broader lesson travels past LatePoint. An unauthenticated field that feeds straight into server-side rendering is a liability no matter which plugin wraps it, and booking forms are exactly the kind of public-facing input that’s easy to forget about once a site is live. Teams running booking and appointment systems as core infrastructure carry more exposure here than most, since a compromised booking flow touches customer data directly. Catching this class of bug before it ships is a normal part of the plugin review we build into WordPress development work, and it’s the same reasoning behind treating custom plugin development as something that needs a security pass, not just a feature checklist.



