<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Appointment Booking Plugin – LatePoint | Calendar &amp; Scheduling for WordPress (&lt;= 5.7.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/appointment-booking-plugin--latepoint--calendar--scheduling-for-wordpress--5.7.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:51:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/appointment-booking-plugin--latepoint--calendar--scheduling-for-wordpress--5.7.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in LatePoint Appointment Booking Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96662/</link><pubDate>Sat, 10 Oct 2026 09:51:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96662/</guid><description>An unauthenticated SQL injection vulnerability in the LatePoint Appointment Booking Plugin allows remote attackers to extract sensitive database information via the booking[service_id] parameter.</description><content:encoded><![CDATA[<p>The Appointment Booking Plugin - LatePoint | Calendar &amp; Scheduling for WordPress is susceptible to an unauthenticated SQL injection vulnerability, identified as CVE-2026-96662. This flaw exists in all versions up to and including 5.7.2. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper SQL query parameterization within the 'booking[service_id]' parameter.</p>
<p>An unauthenticated remote attacker can exploit this weakness by injecting malicious SQL fragments into the 'booking[service_id]' parameter, which the plugin subsequently processes in its backend database queries. Successful exploitation allows an attacker to manipulate the existing SQL statement to perform unauthorized operations, such as extracting sensitive information from the underlying WordPress database. Given the nature of appointment booking plugins, targeted databases may contain PII, contact details, and scheduling information. Defenders should prioritize updating to a patched version once released by the vendor.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-96662 results in unauthorized access to database contents. This impacts the confidentiality of the WordPress database, potentially exposing customer PII, administrator credentials, or configuration data. Affected sectors include any organization relying on the LatePoint plugin for scheduling, such as service-oriented small businesses, healthcare providers, or consultancies.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web application logs for HTTP POST requests to the LatePoint booking endpoints containing SQL special characters or keywords in the 'booking[service_id]' parameter.</li>
<li>Implement a Web Application Firewall (WAF) rule to block requests with suspicious payloads in the 'booking[service_id]' parameter.</li>
<li>Patch the Appointment Booking Plugin - LatePoint to the latest version once available to address the underlying input sanitization flaw.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>sql-injection</category><category>wordpress</category><category>cve</category></item></channel></rss>