SecAlerts
L

LatePoint

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 31 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 14, 2024 to present

31
Total CVEs
11
Critical+High
0
Exploited
11
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
11
Critical/High
Risk Level
33/100
low
🆕 5Fresh (<7d)📈 7 in Last 30 Days

Severity Distribution

Critical
5
High
6
Medium
18
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
XSS
8
2
CSRF
5
3
Code Injection
1
4
Path Traversal
1
5
SQL Injection
1

Most Affected Products

1. Latepoint LatePoint11
2. Latepoint Latepoint Wordpress5
3. Latepoint LatePoint (WordPress plugin)3
4. Latepoint Calendar Booking Plugin for Appointments and Events3
5. Latepoint Appointment Booking Plugin2

Recent Vulnerabilities

See more →
CVE-2026-105198
CVSS 5.3medium

LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR

Oct 8, 2026🔧 No Patch
CVE-2026-105196
CVSS 3.3low

LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API

Oct 8, 2026🔧 No Patch
CVE-2026-105197
CVSS 2.7low

LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR

Oct 8, 2026🔧 No Patch
CVE-2026-17538
CVSS 5.4medium

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Customer PII Modification

Oct 7, 2026🔧 No Patch
CVE-2026-94432
CVSS 5.3medium

Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter

Oct 2, 2026🔧 No Patch
CVE-2026-92966
CVSS 9.1critical

Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field

Oct 1, 2026🔧 No Patch
CVE-2026-13471
CVSS 4.3medium

LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)

Sep 18, 2026🔧 No Patch
CVE-2026-5391
CVSS 6.4medium

LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Aug 6, 2026🔧 No Patch
CVE-2026-11866
CVSS 5.4medium

LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF

Jul 16, 2026🔧 No Patch
CVE-2026-8176
CVSS 7.5high

LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

Jun 16, 2026🔧 No Patch

Monitor LatePoint in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.