{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alatepointthe_appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:latepoint:the_appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92966"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Appointment Booking Plugin – LatePoint | Calendar \u0026 Scheduling for WordPress (\u003c= 5.7.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin-vulnerability","shortcode-injection","cve-2026-92966"],"_cs_type":"advisory","_cs_vendors":["LatePoint"],"content_html":"\u003cp\u003eThe LatePoint | Calendar \u0026amp; Scheduling for WordPress plugin is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0 (CVE-2026-92966). The vulnerability arises because the plugin fails to properly validate user-supplied input before passing it to the WordPress core \u003ccode\u003edo_shortcode\u003c/code\u003e function. An unauthenticated attacker can inject a malicious shortcode payload during the initial booking process. This payload is stored within the system and subsequently executed when the 'Customer Cabinet' block is rendered by the \u003ccode\u003erender_customer_dashboard()\u003c/code\u003e function. Because the WordPress core filter triggers \u003ccode\u003edo_shortcode\u003c/code\u003e at priority 11, the injected shortcode is re-parsed and executed within the context of the user dashboard session. This flaw allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to unauthorized data exposure, privilege escalation, or other actions permitted by the executed shortcodes on the WordPress installation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to the public-facing booking flow provided by the LatePoint plugin.\u003c/li\u003e\n\u003cli\u003eAttacker submits a booking request containing a crafted malicious shortcode payload in a name or metadata field.\u003c/li\u003e\n\u003cli\u003eThe plugin accepts the malicious input and stores it within the WordPress database during the booking registration.\u003c/li\u003e\n\u003cli\u003eThe application processes the stored data as a legitimate booking entry.\u003c/li\u003e\n\u003cli\u003eAn authenticated user (or the attacker via the user dashboard) accesses the Customer Cabinet block.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003erender_customer_dashboard()\u003c/code\u003e function retrieves the stored malicious name data and outputs it to the content stream.\u003c/li\u003e\n\u003cli\u003eThe WordPress \u003ccode\u003edo_shortcode\u003c/code\u003e filter (priority 11) parses the content stream, identifying and executing the injected malicious shortcode.\u003c/li\u003e\n\u003cli\u003eThe shortcode executes with the privileges of the rendering user, resulting in unauthorized operations or information disclosure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary shortcodes on affected WordPress sites. This can lead to unauthorized data access, the modification of content, or potential privilege escalation depending on the specific shortcodes available within the site's environment. All versions of the LatePoint plugin through 5.7.0 are affected, posing a significant risk to WordPress sites utilizing the plugin for scheduling.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the LatePoint plugin to the latest patched version immediately (as of 5.7.0, a fix should be sought in subsequent releases).\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests to the booking endpoint containing bracketed characters (e.g., \u003ccode\u003e[\u003c/code\u003e or \u003ccode\u003e]\u003c/code\u003e) and known WordPress shortcode identifiers.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect and sanitize input parameters in booking requests for shortcode syntax.\u003c/li\u003e\n\u003cli\u003eAudit existing bookings and user data in the WordPress database for anomalous entries that include shortcode characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T06:38:51Z","date_published":"2026-10-01T06:38:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-latepoint-vulnerability/","summary":"The LatePoint WordPress plugin is vulnerable to unauthenticated arbitrary shortcode execution due to improper input validation during the booking flow.","title":"Arbitrary Shortcode Execution in LatePoint WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-latepoint-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:latepoint:the_appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}