CVE-2026-11866: LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Appointment Booking Pluginto a version that resolves this vulnerability.Fixed in 5.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11866?
The severity of CVE-2026-11866 is rated at risk level 45.
What actions can an attacker perform using CVE-2026-11866?
An attacker can perform privileged actions such as overwriting the booking form configuration or disconnecting connected accounts.
How do I fix CVE-2026-11866?
To fix CVE-2026-11866, update the LatePoint Appointment Booking Plugin to version 5.6.3 or later.
Which versions of the LatePoint plugin are affected by CVE-2026-11866?
CVE-2026-11866 affects versions of the LatePoint Appointment Booking Plugin prior to 5.6.3.
What type of vulnerability is CVE-2026-11866 classified as?
CVE-2026-11866 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.