CVE-2026-92966 is a critical (CVSS 9.1) flaw in the LatePoint appointment booking plugin for WordPress that lets unauthenticated attackers plant shortcodes through the booking flow and have them executed later.
What Is It
CVE-2026-92966 is an arbitrary shortcode execution vulnerability (CWE-94, Improper Control of Generation of Code) in the "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress." The plugin lets users run an action that does not properly validate a value before passing it to do_shortcode.
According to the NVD description, an attacker plants the payload during the unauthenticated booking flow. It fires when the Customer Cabinet block, rendered by render_customer_dashboard(), writes the stored name into the content stream. WordPress core's do_shortcode filter, running at priority 11, then re-parses and executes it.
Wordfence reported the issue. NVD published it on 2026-10-01, and its status is currently "Deferred."
Why It Matters
Wordfence scores the flaw CVSS 3.1 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N:
- Network-reachable and low complexity
- No privileges and no user interaction required
- High confidentiality and integrity impact. Availability impact: none.
The entry point is the public booking flow, so any site that exposes LatePoint booking to visitors has an unauthenticated attack surface. Arbitrary shortcode execution lets an attacker run any shortcode registered on the site. Depending on the other plugins installed, that can expose or change data.
KEV status: CVE-2026-92966 is not in the CISA Known Exploited Vulnerabilities catalog. The supplied data does not confirm any active exploitation.
What's Vulnerable
- Vendor: latepoint
- Product: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
- Affected versions: All versions up to and including 5.7.0
The NVD references point to the affected code in the 5.7.0 release: lib/helpers/blocks_helper.php, lib/models/customer_model.php and lib/views/customer_cabinet/dashboard.php.
Patch Status
The NVD record lists every version through 5.7.0 as affected. Its references include the blocks_helper.php file from a 5.7.1 tag in the WordPress plugin repository, which suggests a later release changed the affected code. The record does not explicitly name a fixed version. No CISA required action applies because the CVE is not in KEV.
Administrators should update LatePoint to a version later than 5.7.0. They should check the Wordfence advisory to confirm which release contains the fix.