SQL Injection in LatePoint Appointment Booking Plugin for WordPress
An unauthenticated SQL injection vulnerability in the LatePoint Appointment Booking Plugin allows remote attackers to extract sensitive database information via the booking[service_id] parameter.
CVE search metadata
CVE search record: CVE-2026-96662. Severity: high. CVSS: 7.5. KEV: no. Product: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (<= 5.7.2). Brief: SQL Injection in LatePoint Appointment Booking Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96662/
The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress is susceptible to an unauthenticated SQL injection vulnerability, identified as CVE-2026-96662. This flaw exists in all versions up to and including 5.7.2. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper SQL query parameterization within the 'booking[service_id]' parameter.
An unauthenticated remote attacker can exploit this weakness by injecting malicious SQL fragments into the 'booking[service_id]' parameter, which the plugin subsequently processes in its backend database queries. Successful exploitation allows an attacker to manipulate the existing SQL statement to perform unauthorized operations, such as extracting sensitive information from the underlying WordPress database. Given the nature of appointment booking plugins, targeted databases may contain PII, contact details, and scheduling information. Defenders should prioritize updating to a patched version once released by the vendor.
Impact
Successful exploitation of CVE-2026-96662 results in unauthorized access to database contents. This impacts the confidentiality of the WordPress database, potentially exposing customer PII, administrator credentials, or configuration data. Affected sectors include any organization relying on the LatePoint plugin for scheduling, such as service-oriented small businesses, healthcare providers, or consultancies.
Recommendation
- Monitor web application logs for HTTP POST requests to the LatePoint booking endpoints containing SQL special characters or keywords in the 'booking[service_id]' parameter.
- Implement a Web Application Firewall (WAF) rule to block requests with suspicious payloads in the 'booking[service_id]' parameter.
- Patch the Appointment Booking Plugin - LatePoint to the latest version once available to address the underlying input sanitization flaw.
Immediate actions
Review web server logs for exploitation attempts targeting the booking[service_id] parameter
Mitigations
Upgrade LatePoint Appointment Booking Plugin to the patched version once released
CVE-2026-96662
Detection coverage 1
Detect CVE-2026-96662 - SQL Injection in LatePoint Booking Plugin
highDetects exploitation of CVE-2026-96662 by monitoring for SQL keywords and special characters in the booking[service_id] parameter.
Detection queries are available on the platform. Get full rules →