Sceawere

Vulnerability Detail

CVE-2026-96662UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LatePoint SQL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
latepoint
Product
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-10T08:17:08.033Z",
  "pubdate": "2026-10-10T08:17:08.033Z",
  "executiveSummary": "The LatePoint | Calendar & Scheduling for WordPress plugin is susceptible to an unauthenticated SQL Injection vulnerability. This flaw arises from improper sanitization and inadequate parameter preparation within the booking process. The vulnerability resides in the 'booking[service_id]' parameter, which fails to neutralize malicious input before processing database queries. An attacker can leverage this weakness to manipulate existing SQL commands, potentially exposing sensitive database content, compromising user data, or altering system records. Since the exploit does not require authentication, the risk is severe, allowing remote, unauthenticated actors to interact directly with the backend database. Organizations using versions 5.7.2 and below are at high risk of unauthorized information disclosure and data integrity compromise. Immediate remediation is required to secure the database layer.",
  "technicalDetails": "The vulnerability is classified as a classic SQL Injection (SQLi) resulting from insufficient escaping of user-supplied data and the absence of prepared statements in the plugin's data handling layer. Specifically, the 'booking[service_id]' parameter is processed by the plugin without rigorous validation or parameterization of the SQL syntax, allowing malicious actors to inject arbitrary SQL fragments into the underlying database queries.\nThe root cause is identified as the application's failure to employ secure database abstraction techniques, such as the WordPress $wpdb->prepare() function, when constructing queries that incorporate user input. By appending crafted SQL syntax to the 'booking[service_id]' parameter, an attacker can effectively manipulate the logic of the original database query.\nThe attack flow proceeds as follows: An unauthenticated attacker sends a crafted HTTP request to the target WordPress installation, specifically targeting the endpoint responsible for handling LatePoint booking requests. Within the POST payload, the 'booking[service_id]' parameter is modified to include SQL injection syntax, such as UNION-based injection or boolean-based inference techniques. Because the application logic fails to sanitize this input, the malicious query is concatenated into the plugin's internal database request. The database server executes the resulting manipulated query, effectively bypassing expected input boundaries. This allows the attacker to extract information from arbitrary tables within the WordPress database, including wp_users, configuration settings, or private booking data.\nThe vulnerability affects all versions of the LatePoint plugin up to and including 5.7.2. The lack of authentication requirements facilitates a high level of accessibility for external attackers, as the malicious payload can be delivered over standard HTTP/HTTPS channels without prior access to the WordPress administrative interface. The scope of impact is limited only by the privileges associated with the database user configured for the WordPress site, which typically possesses read/write access to all relevant application data. Persistent exploitation leads to unauthorized data exfiltration, and depending on database configuration, could lead to further system compromise."
}
CVE-2026-96662: LatePoint SQL Injection Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere