{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alatepointappointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:latepoint:appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-96662"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Appointment Booking Plugin – LatePoint | Calendar \u0026 Scheduling for WordPress (\u003c= 5.7.2)"],"_cs_severities":["high"],"_cs_tags":["web-application","sql-injection","wordpress","cve"],"_cs_type":"advisory","_cs_vendors":["LatePoint"],"content_html":"\u003cp\u003eThe Appointment Booking Plugin - LatePoint | Calendar \u0026amp; Scheduling for WordPress is susceptible to an unauthenticated SQL injection vulnerability, identified as CVE-2026-96662. This flaw exists in all versions up to and including 5.7.2. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper SQL query parameterization within the 'booking[service_id]' parameter.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can exploit this weakness by injecting malicious SQL fragments into the 'booking[service_id]' parameter, which the plugin subsequently processes in its backend database queries. Successful exploitation allows an attacker to manipulate the existing SQL statement to perform unauthorized operations, such as extracting sensitive information from the underlying WordPress database. Given the nature of appointment booking plugins, targeted databases may contain PII, contact details, and scheduling information. Defenders should prioritize updating to a patched version once released by the vendor.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-96662 results in unauthorized access to database contents. This impacts the confidentiality of the WordPress database, potentially exposing customer PII, administrator credentials, or configuration data. Affected sectors include any organization relying on the LatePoint plugin for scheduling, such as service-oriented small businesses, healthcare providers, or consultancies.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web application logs for HTTP POST requests to the LatePoint booking endpoints containing SQL special characters or keywords in the 'booking[service_id]' parameter.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block requests with suspicious payloads in the 'booking[service_id]' parameter.\u003c/li\u003e\n\u003cli\u003ePatch the Appointment Booking Plugin - LatePoint to the latest version once available to address the underlying input sanitization flaw.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T09:51:57Z","date_published":"2026-10-10T09:51:57Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96662/","summary":"An unauthenticated SQL injection vulnerability in the LatePoint Appointment Booking Plugin allows remote attackers to extract sensitive database information via the booking[service_id] parameter.","title":"SQL Injection in LatePoint Appointment Booking Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96662/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:latepoint:appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}