SecAlerts
LatePoint logo

LatePoint

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 24 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 14, 2024 to present

24
Total CVEs
10
Critical+High
0
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
36/100
low
🆕 1Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
4
High
6
Medium
14
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
XSS
8
2
CSRF
5
3
Path Traversal
1
4
SQL Injection
1

Most Affected Products

1. Latepoint LatePoint9
2. Latepoint Latepoint Wordpress5
3. Latepoint LatePoint (WordPress plugin)3
4. Latepoint Calendar Booking Plugin for Appointments and Events3
5. Latepoint LatePoint plugin for WordPress2

Recent Vulnerabilities

See more →
CVE-2026-5391
CVSS 6.4medium

LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

8/6/2026🔧 No Patch
CVE-2026-11866
CVSS 5.4medium

LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF

7/16/2026🔧 No Patch
CVE-2026-8176
CVSS 7.5high

LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

6/16/2026🔧 No Patch
CVE-2026-9719
CVSS 4.3EPSS 0%medium

LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

6/5/2026🔧 No Patch
CVE-2026-5365
CVSS 4.3medium

LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route

5/14/2026🔧 No Patch
CVE-2026-7652
CVSS 5.3EPSS 0%medium

LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism

5/9/2026🔧 No Patch
CVE-2026-7448
CVSS 7.2EPSS 0%high

LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'first_name' Parameter

5/6/2026🔧 No Patch
CVE-2026-7457
CVSS 6.4EPSS 0%medium

LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update

5/6/2026🔧 No Patch
CVE-2026-6741
CVSS 8.8EPSS 0%high

LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability

4/27/2026🔧 No Patch
CVE-2026-5234
CVSS 5.3EPSS 0%medium

LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID

4/17/2026🔧 No Patch

Monitor LatePoint in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.