Junglewise Threat Intelligence

CVE-2026-4785: LatePoint Calendar Booking Stored XSS in latepoint_resources shortcode

CVE-2026-4785 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Technologies: LatePoint. Vendors: LatePoint.

Executive brief

LatePoint is a WordPress plugin used by businesses to manage appointment bookings and event scheduling. A security vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping on the 'button_caption' parameter within the [latepoint_resources] shortcode. This vulnerability is specifically triggered when the 'items' parameter is set to 'bundles'. An authenticated attacker with contributor-level permissions or higher can exploit this to inject arbitrary web scripts into a page. These scripts will execute in the context of any user's browser who visits the affected page. The issue was addressed in a changeset following version 5.3.0.

Affected products

  • LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events up to and including 5.3.0

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References

Related threats