PT-2026-7813 · WordPress · Latepoint – Calendar Booking Plugin For Appointments/Events

Chiao-Lin Yu

·

Published

2026-02-12

·

Updated

2026-02-12

·

CVE-2026-1537

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.2.7
Description The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check within the load step() function. An unauthenticated attacker can view booking information, including customer names, email addresses, phone numbers, appointment times, and service details.
Recommendations Update to version 5.2.7 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1537

Affected Products

Latepoint – Calendar Booking Plugin For Appointments/Events