SecAlerts
L

LatePoint

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 25 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 14, 2024 to present

25
Total CVEs
10
Critical+High
0
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
33/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
4
High
6
Medium
15
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
XSS
8
2
CSRF
5
3
Path Traversal
1
4
SQL Injection
1

Most Affected Products

1. Latepoint LatePoint9
2. Latepoint Latepoint Wordpress5
3. Latepoint LatePoint (WordPress plugin)3
4. Latepoint Calendar Booking Plugin for Appointments and Events3
5. Latepoint LatePoint plugin for WordPress2

Recent Vulnerabilities

See more →
CVE-2026-13471
CVSS 4.3medium

LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)

Sep 18, 2026🔧 No Patch
CVE-2026-5391
CVSS 6.4medium

LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Aug 6, 2026🔧 No Patch
CVE-2026-11866
CVSS 5.4medium

LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF

Jul 16, 2026🔧 No Patch
CVE-2026-8176
CVSS 7.5high

LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

Jun 16, 2026🔧 No Patch
CVE-2026-9719
CVSS 4.3EPSS 0%medium

LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

Jun 5, 2026🔧 No Patch
CVE-2026-5365
CVSS 4.3medium

LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route

May 14, 2026🔧 No Patch
CVE-2026-7652
CVSS 5.3EPSS 0%medium

LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism

May 9, 2026🔧 No Patch
CVE-2026-7448
CVSS 7.2EPSS 0%high

LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'first_name' Parameter

May 6, 2026🔧 No Patch
CVE-2026-7457
CVSS 6.4EPSS 0%medium

LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update

May 6, 2026🔧 No Patch
CVE-2026-6741
CVSS 8.8EPSS 0%high

LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability

Apr 27, 2026🔧 No Patch

Monitor LatePoint in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.