ConicPlex

Start Your Project

A darkened appointment-business reception desk at night with a monitor showing an abstract blue booking calendar grid, a brass keycard resting near the keyboard, and a phone face-down on the desk.

On this Page

LatePoint Patches a Critical Unauthenticated Shortcode Injection Flaw (CVE-2026-92966)

Aftab Memon

October 7, 2026

LatePoint, a WordPress appointment booking plugin running on more than 100,000 service-business sites, has patched a critical vulnerability that let unauthenticated attackers inject and run arbitrary shortcodes through its public booking form. Tracked as CVE-2026-92966 and rated 9.1 (critical) on the CVSS scale, the flaw affects every version up to and including 5.7.0. LatePoint fixed it quietly in version 5.7.1, released September 25, 2026, after Wordfence reported the issue, and the CVE itself went public on October 1. If a site is still running 5.7.0 or older, this is worth checking today.

How the Flaw Actually Works

The bug sits in how LatePoint renders a customer’s name inside its Customer Cabinet dashboard. Anyone can submit a booking without an account, and the plugin never validated what landed in the name field before storing it. Plant a WordPress shortcode there instead of a real name, and once that booking shows up in the customer dashboard, WordPress’s own do_shortcode filter parses and runs it. No login, no admin tricked into clicking anything, nothing beyond filling out a public form.

Wordfence and NVD classify this as CWE-94, code injection. The actual damage a shortcode can do depends on what else is installed. Some page builders and utility plugins expose shortcodes that touch files, templates, or server-side logic well beyond basic formatting, so the real blast radius varies site to site, which is part of why this scored a 9.1 instead of something more contained.

Who Should Act, and What to Check

Any site taking bookings through LatePoint, salons, clinics, tutors, consultants, fitness studios, is exposed if it hasn’t updated past 5.7.0. A few concrete steps:

  • Update LatePoint to version 5.7.1 or later now, before anything else.
  • Scan recent booking entries for odd content in name or customer fields, especially anything wrapped in square brackets.
  • Check which other active plugins register shortcodes with real side effects (file operations, template includes, settings changes), since those are what turn this bug from annoying into dangerous.
  • If a suspicious booking predates the patch and an admin has logged in since, rotate credentials and review the user list for accounts that shouldn’t be there.

The broader lesson travels past LatePoint. An unauthenticated field that feeds straight into server-side rendering is a liability no matter which plugin wraps it, and booking forms are exactly the kind of public-facing input that’s easy to forget about once a site is live. Teams running booking and appointment systems as core infrastructure carry more exposure here than most, since a compromised booking flow touches customer data directly. Catching this class of bug before it ships is a normal part of the plugin review we build into WordPress development work, and it’s the same reasoning behind treating custom plugin development as something that needs a security pass, not just a feature checklist.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Guides

An empty clinic reception desk at night with a tablet on the counter displaying a glowing blue chat interface next to a privacy screen

How to Build a HIPAA-Compliant AI Chatbot for a Healthcare Website

What actually makes an AI chatbot HIPAA compliant: a signed BAA, encryption, patient verification, and audit logging, plus when a…

Husen Memon

October 7, 2026

Plugins

Illustration of a day-schedule column with appointment blocks separated by highlighted buffer time gaps, next to a clock face, representing buffer time in WordPress booking plugins

How to Add Buffer Time between Appointments in a WordPress Booking Plugin (4 Plugins Compared)

A practical comparison of WordPress booking plugins that let you add buffer time between appointments, with real setup steps, pricing,…

Husen Memon

October 7, 2026

News & Updates

A dark developer workspace at night lit in blue tones, with a file folder slipping out of an open cabinet beside a laptop and monitor, symbolizing an unauthorized file access vulnerability

Atlassian Patches a Critical Unauthenticated File Access Flaw across Eight Products (CVE-2026-21589)

Atlassian patched CVE-2026-21589, a 9.3-severity path traversal flaw letting unauthenticated attackers read files across Jira, Confluence, Bitbucket, and five other…

Sameer Malek

October 6, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant