PT-2026-7813 · WordPress · Latepoint – Calendar Booking Plugin For Appointments/Events

·

CVE-2026-1537

·

Published

2026-02-12

·

Updated

2026-02-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.2.7
Description The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check within the load step() function. An unauthenticated attacker can view booking information, including customer names, email addresses, phone numbers, appointment times, and service details.
Recommendations Update to version 5.2.7 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1537

Affected Products

Latepoint – Calendar Booking Plugin For Appointments/Events