Sceawere
Vulnerability Detail
CVE-2026-96662UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LatePoint SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- latepoint
- Product
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-10T08:17:08.033Z",
"pubdate": "2026-10-10T08:17:08.033Z",
"executiveSummary": "The LatePoint | Calendar & Scheduling for WordPress plugin is susceptible to an unauthenticated SQL Injection vulnerability. This flaw arises from improper sanitization and inadequate parameter preparation within the booking process. The vulnerability resides in the 'booking[service_id]' parameter, which fails to neutralize malicious input before processing database queries. An attacker can leverage this weakness to manipulate existing SQL commands, potentially exposing sensitive database content, compromising user data, or altering system records. Since the exploit does not require authentication, the risk is severe, allowing remote, unauthenticated actors to interact directly with the backend database. Organizations using versions 5.7.2 and below are at high risk of unauthorized information disclosure and data integrity compromise. Immediate remediation is required to secure the database layer.",
"technicalDetails": "The vulnerability is classified as a classic SQL Injection (SQLi) resulting from insufficient escaping of user-supplied data and the absence of prepared statements in the plugin's data handling layer. Specifically, the 'booking[service_id]' parameter is processed by the plugin without rigorous validation or parameterization of the SQL syntax, allowing malicious actors to inject arbitrary SQL fragments into the underlying database queries.\nThe root cause is identified as the application's failure to employ secure database abstraction techniques, such as the WordPress $wpdb->prepare() function, when constructing queries that incorporate user input. By appending crafted SQL syntax to the 'booking[service_id]' parameter, an attacker can effectively manipulate the logic of the original database query.\nThe attack flow proceeds as follows: An unauthenticated attacker sends a crafted HTTP request to the target WordPress installation, specifically targeting the endpoint responsible for handling LatePoint booking requests. Within the POST payload, the 'booking[service_id]' parameter is modified to include SQL injection syntax, such as UNION-based injection or boolean-based inference techniques. Because the application logic fails to sanitize this input, the malicious query is concatenated into the plugin's internal database request. The database server executes the resulting manipulated query, effectively bypassing expected input boundaries. This allows the attacker to extract information from arbitrary tables within the WordPress database, including wp_users, configuration settings, or private booking data.\nThe vulnerability affects all versions of the LatePoint plugin up to and including 5.7.2. The lack of authentication requirements facilitates a high level of accessibility for external attackers, as the malicious payload can be delivered over standard HTTP/HTTPS channels without prior access to the WordPress administrative interface. The scope of impact is limited only by the privileges associated with the database user configured for the WordPress site, which typically possesses read/write access to all relevant application data. Persistent exploitation leads to unauthorized data exfiltration, and depending on database configuration, could lead to further system compromise."
}