Skip to content
Threat Feed
high advisory

SQL Injection in LatePoint Appointment Booking Plugin for WordPress

An unauthenticated SQL injection vulnerability in the LatePoint Appointment Booking Plugin allows remote attackers to extract sensitive database information via the booking[service_id] parameter.

CVE search metadata

CVE search record: CVE-2026-96662. Severity: high. CVSS: 7.5. KEV: no. Product: Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (<= 5.7.2). Brief: SQL Injection in LatePoint Appointment Booking Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96662/

The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress is susceptible to an unauthenticated SQL injection vulnerability, identified as CVE-2026-96662. This flaw exists in all versions up to and including 5.7.2. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper SQL query parameterization within the 'booking[service_id]' parameter.

An unauthenticated remote attacker can exploit this weakness by injecting malicious SQL fragments into the 'booking[service_id]' parameter, which the plugin subsequently processes in its backend database queries. Successful exploitation allows an attacker to manipulate the existing SQL statement to perform unauthorized operations, such as extracting sensitive information from the underlying WordPress database. Given the nature of appointment booking plugins, targeted databases may contain PII, contact details, and scheduling information. Defenders should prioritize updating to a patched version once released by the vendor.

Impact

Successful exploitation of CVE-2026-96662 results in unauthorized access to database contents. This impacts the confidentiality of the WordPress database, potentially exposing customer PII, administrator credentials, or configuration data. Affected sectors include any organization relying on the LatePoint plugin for scheduling, such as service-oriented small businesses, healthcare providers, or consultancies.

Recommendation

  • Monitor web application logs for HTTP POST requests to the LatePoint booking endpoints containing SQL special characters or keywords in the 'booking[service_id]' parameter.
  • Implement a Web Application Firewall (WAF) rule to block requests with suspicious payloads in the 'booking[service_id]' parameter.
  • Patch the Appointment Booking Plugin - LatePoint to the latest version once available to address the underlying input sanitization flaw.

Immediate actions

Review web server logs for exploitation attempts targeting the booking[service_id] parameter

SOC 24h

Mitigations

Upgrade LatePoint Appointment Booking Plugin to the patched version once released

immediate IT Operations

CVE-2026-96662

Detection coverage 1

Detect CVE-2026-96662 - SQL Injection in LatePoint Booking Plugin

high

Detects exploitation of CVE-2026-96662 by monitoring for SQL keywords and special characters in the booking[service_id] parameter.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →