CVE-2026-15250
LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel
CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
5th
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.
| Vendor | unknown |
| Product | appointment booking plugin |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown appointment booking plugin
Be the first to know when new medium vulnerabilities affecting unknown appointment booking plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Appointment Booking Plugin
0 < 5.6.8
References
Credits
Revanth Hari Narayana Matte WPScan