<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>The Appointment Booking Plugin – LatePoint | Calendar &amp; Scheduling for WordPress (&lt;= 5.7.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/the-appointment-booking-plugin--latepoint--calendar--scheduling-for-wordpress--5.7.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 06:38:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/the-appointment-booking-plugin--latepoint--calendar--scheduling-for-wordpress--5.7.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Shortcode Execution in LatePoint WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-latepoint-vulnerability/</link><pubDate>Thu, 01 Oct 2026 06:38:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-latepoint-vulnerability/</guid><description>The LatePoint WordPress plugin is vulnerable to unauthenticated arbitrary shortcode execution due to improper input validation during the booking flow.</description><content:encoded><![CDATA[<p>The LatePoint | Calendar &amp; Scheduling for WordPress plugin is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0 (CVE-2026-92966). The vulnerability arises because the plugin fails to properly validate user-supplied input before passing it to the WordPress core <code>do_shortcode</code> function. An unauthenticated attacker can inject a malicious shortcode payload during the initial booking process. This payload is stored within the system and subsequently executed when the 'Customer Cabinet' block is rendered by the <code>render_customer_dashboard()</code> function. Because the WordPress core filter triggers <code>do_shortcode</code> at priority 11, the injected shortcode is re-parsed and executed within the context of the user dashboard session. This flaw allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to unauthorized data exposure, privilege escalation, or other actions permitted by the executed shortcodes on the WordPress installation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker navigates to the public-facing booking flow provided by the LatePoint plugin.</li>
<li>Attacker submits a booking request containing a crafted malicious shortcode payload in a name or metadata field.</li>
<li>The plugin accepts the malicious input and stores it within the WordPress database during the booking registration.</li>
<li>The application processes the stored data as a legitimate booking entry.</li>
<li>An authenticated user (or the attacker via the user dashboard) accesses the Customer Cabinet block.</li>
<li>The <code>render_customer_dashboard()</code> function retrieves the stored malicious name data and outputs it to the content stream.</li>
<li>The WordPress <code>do_shortcode</code> filter (priority 11) parses the content stream, identifying and executing the injected malicious shortcode.</li>
<li>The shortcode executes with the privileges of the rendering user, resulting in unauthorized operations or information disclosure.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary shortcodes on affected WordPress sites. This can lead to unauthorized data access, the modification of content, or potential privilege escalation depending on the specific shortcodes available within the site's environment. All versions of the LatePoint plugin through 5.7.0 are affected, posing a significant risk to WordPress sites utilizing the plugin for scheduling.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the LatePoint plugin to the latest patched version immediately (as of 5.7.0, a fix should be sought in subsequent releases).</li>
<li>Monitor web server logs for suspicious requests to the booking endpoint containing bracketed characters (e.g., <code>[</code> or <code>]</code>) and known WordPress shortcode identifiers.</li>
<li>Implement Web Application Firewall (WAF) rules to inspect and sanitize input parameters in booking requests for shortcode syntax.</li>
<li>Audit existing bookings and user data in the WordPress database for anomalous entries that include shortcode characters.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>plugin-vulnerability</category><category>shortcode-injection</category><category>cve-2026-92966</category></item></channel></rss>