Junglewise Threat Intelligence

CVE-2026-9719: LatePoint WordPress Plugin CSRF in change_status function

CVE-2026-9719 · Severity: medium · CVSS 4.3 · Published 2026-06-06

Technologies: LatePoint – Calendar Booking Plugin for Appointments and Events. Vendors: LatePoint.

Executive brief

The LatePoint plugin for WordPress, which manages appointment bookings and event scheduling, contains a security flaw that allows attackers to manipulate invoice records. By tricking a site administrator into clicking a malicious link, an attacker can change the status of invoices, such as marking unpaid bills as paid. This could lead to financial discrepancies and unauthorized service fulfillment without actual payment.

Technical details

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'change_status' function within the invoices controller. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it (e.g., via social engineering or a malicious link). Successful exploitation allows the attacker to modify the status of any invoice, including marking unpaid invoices as 'paid'. The vulnerability affects all versions up to and including 5.6.0; a patch was introduced in subsequent updates.

Affected products

  • LatePoint LatePoint – Calendar Booking Plugin for Appointments and Events up to, and including, 5.6.0

Timeline

  • 2026-06-06: advisory: NVD publication date
  • 2026-06-05: disclosed: Wordfence disclosure date

References

Related threats