Junglewise Threat Intelligence

CVE-2026-57714: LatePoint SQL injection in WordPress plugin

CVE-2026-57714 · Severity: critical · CVSS 9.3 · Published 2026-07-13

Technologies: LatePoint. Vendors: LatePoint.

Executive brief

LatePoint is a popular appointment booking and scheduling plugin for WordPress websites. A critical security flaw has been identified that allows unauthorized individuals to perform 'blind' SQL injection attacks. This could allow an attacker to extract sensitive information from the website's database, potentially compromising customer data or administrative details, and could lead to minor service disruptions.

Technical details

A Blind SQL Injection vulnerability exists in the LatePoint plugin for WordPress (versions <= 5.6.3) due to insufficient sanitization of user-supplied input used in SQL queries (CWE-89). The vulnerability can be exploited remotely over the network without authentication (PR:N) and requires no user interaction. An attacker can leverage this to extract sensitive data from the database by observing differences in application responses to crafted boolean or time-based payloads. The issue is reportedly addressed in version 5.6.4.

Affected products

  • LatePoint LatePoint through 5.6.3

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References

Related threats