Skip to content
Threat Feed
critical advisory

Arbitrary Shortcode Execution in LatePoint WordPress Plugin

The LatePoint WordPress plugin is vulnerable to unauthenticated arbitrary shortcode execution due to improper input validation during the booking flow.

CVE search metadata

CVE search record: CVE-2026-92966. Severity: critical. CVSS: 9.1. KEV: no. Product: The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (<= 5.7.0). Brief: Arbitrary Shortcode Execution in LatePoint WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-latepoint-vulnerability/

The LatePoint | Calendar & Scheduling for WordPress plugin is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0 (CVE-2026-92966). The vulnerability arises because the plugin fails to properly validate user-supplied input before passing it to the WordPress core do_shortcode function. An unauthenticated attacker can inject a malicious shortcode payload during the initial booking process. This payload is stored within the system and subsequently executed when the 'Customer Cabinet' block is rendered by the render_customer_dashboard() function. Because the WordPress core filter triggers do_shortcode at priority 11, the injected shortcode is re-parsed and executed within the context of the user dashboard session. This flaw allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to unauthorized data exposure, privilege escalation, or other actions permitted by the executed shortcodes on the WordPress installation.

Attack Chain

  1. Attacker navigates to the public-facing booking flow provided by the LatePoint plugin.
  2. Attacker submits a booking request containing a crafted malicious shortcode payload in a name or metadata field.
  3. The plugin accepts the malicious input and stores it within the WordPress database during the booking registration.
  4. The application processes the stored data as a legitimate booking entry.
  5. An authenticated user (or the attacker via the user dashboard) accesses the Customer Cabinet block.
  6. The render_customer_dashboard() function retrieves the stored malicious name data and outputs it to the content stream.
  7. The WordPress do_shortcode filter (priority 11) parses the content stream, identifying and executing the injected malicious shortcode.
  8. The shortcode executes with the privileges of the rendering user, resulting in unauthorized operations or information disclosure.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary shortcodes on affected WordPress sites. This can lead to unauthorized data access, the modification of content, or potential privilege escalation depending on the specific shortcodes available within the site's environment. All versions of the LatePoint plugin through 5.7.0 are affected, posing a significant risk to WordPress sites utilizing the plugin for scheduling.

Recommendation

  • Update the LatePoint plugin to the latest patched version immediately (as of 5.7.0, a fix should be sought in subsequent releases).
  • Monitor web server logs for suspicious requests to the booking endpoint containing bracketed characters (e.g., [ or ]) and known WordPress shortcode identifiers.
  • Implement Web Application Firewall (WAF) rules to inspect and sanitize input parameters in booking requests for shortcode syntax.
  • Audit existing bookings and user data in the WordPress database for anomalous entries that include shortcode characters.

Immediate actions

Upgrade LatePoint to the latest version beyond 5.7.0.

IT Operations 24h

Mitigations

Monitor booking endpoints for shortcode-like characters in input fields.

immediate SOC

CVE-2026-92966