๐Ÿ” CVE Alert

CVE-2026-15250

MEDIUM 5.3

LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
5th

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.

Vendor unknown
Product appointment booking plugin
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown appointment booking plugin

Be the first to know when new medium vulnerabilities affecting unknown appointment booking plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Appointment Booking Plugin
0 < 5.6.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/2609e202-9be3-42b0-a1fb-ace310b93bd0/

Credits

Revanth Hari Narayana Matte WPScan