CVE-2025-6815: LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘service[name]’ parameter in all versions up to, and including, 5.1.94 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6815?
CVE-2025-6815 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting.
How do I fix CVE-2025-6815?
To fix CVE-2025-6815, update the LatePoint Calendar Booking Plugin for Appointments and Events to version 5.1.95 or later.
What versions are affected by CVE-2025-6815?
All versions of the LatePoint Calendar Booking Plugin for Appointments and Events up to and including 5.1.94 are affected by CVE-2025-6815.
What type of vulnerability is CVE-2025-6815?
CVE-2025-6815 is a stored cross-site scripting (XSS) vulnerability due to insufficient input sanitization.
What is the impact of CVE-2025-6815?
The impact of CVE-2025-6815 may include unauthorized script execution in the context of a user's web browser, potentially leading to data theft.