Cyber & AI intelligence
Wasteland.
Briefs indexed2957
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-92966 2026-10-01

LatePoint WordPress Plugin Flaw Lets Unauthenticated Attackers Execute Arbitrary Shortcodes (CVE-2026-92966)

"CVE-2026-92966 is a critical (CVSS 9.1) flaw in the LatePoint appointment booking plugin for WordPress that lets unauthenticated attackers plant shortcodes through the booking flow and have them executed later."

CVE-2026-92966 is a critical (CVSS 9.1) flaw in the LatePoint appointment booking plugin for WordPress that lets unauthenticated attackers plant shortcodes through the booking flow and have them executed later.

What Is It

CVE-2026-92966 is an arbitrary shortcode execution vulnerability (CWE-94, Improper Control of Generation of Code) in the "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress." The plugin lets users run an action that does not properly validate a value before passing it to do_shortcode.

According to the NVD description, an attacker plants the payload during the unauthenticated booking flow. It fires when the Customer Cabinet block, rendered by render_customer_dashboard(), writes the stored name into the content stream. WordPress core's do_shortcode filter, running at priority 11, then re-parses and executes it.

Wordfence reported the issue. NVD published it on 2026-10-01, and its status is currently "Deferred."

Why It Matters

Wordfence scores the flaw CVSS 3.1 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N:

The entry point is the public booking flow, so any site that exposes LatePoint booking to visitors has an unauthenticated attack surface. Arbitrary shortcode execution lets an attacker run any shortcode registered on the site. Depending on the other plugins installed, that can expose or change data.

KEV status: CVE-2026-92966 is not in the CISA Known Exploited Vulnerabilities catalog. The supplied data does not confirm any active exploitation.

What's Vulnerable

The NVD references point to the affected code in the 5.7.0 release: lib/helpers/blocks_helper.php, lib/models/customer_model.php and lib/views/customer_cabinet/dashboard.php.

Patch Status

The NVD record lists every version through 5.7.0 as affected. Its references include the blocks_helper.php file from a 5.7.1 tag in the WordPress plugin repository, which suggests a later release changed the affected code. The record does not explicitly name a fixed version. No CISA required action applies because the CVE is not in KEV.

Administrators should update LatePoint to a version later than 5.7.0. They should check the Wordfence advisory to confirm which release contains the fix.

Sources