External risk intelligence

LatePoint WordPress Plugin Arbitrary Shortcode Execution

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92966

The vulnerability exists in a WordPress appointment booking plugin. Such plugins are designed to be public-facing by default to allow unauthenticated users to interact with booking flows, scheduling calendars, and customer dashboards directly from the internet.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in a popular WordPress plugin that handles appointment bookings. The flaw allows unauthenticated attackers to potentially execute unauthorized commands on affected systems, which could lead to significant data compromise or disruption. The main concern is to confirm if this specific plugin is in use and, if so, to assess the potential exposure.

  • Plugin flaw allows unauthorized command execution.
  • Potentially impacts public-facing booking systems.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this by submitting a booking that includes malicious shortcode within their name. This shortcode is then processed and executed by the WordPress core when the customer's cabinet is displayed, potentially leading to unauthorized actions on the site.

  • Requires no user authentication.
  • Shortcode execution during booking display.
  • Unauthenticated arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could execute arbitrary shortcodes through the Appointment Booking Plugin for WordPress when users interact with the unauthenticated booking flow. This could impact system data and service behavior when the Customer Cabinet block processes stored customer names.

  • Arbitrary shortcode execution.
  • Unauthenticated booking flow.
  • System data and service behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Appointment Booking Plugin for WordPress likely impacts website owners and platform administrators. The first step is to identify all WordPress sites using this plugin, confirm if they are externally accessible, and determine their business criticality to prioritize remediation efforts.

  • Identify accountable application owners.
  • Verify external accessibility and criticality.
  • Plan and coordinate remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the LatePoint WordPress plugin?

The Appointment Booking Plugin – LatePoint is a tool for WordPress websites that manages scheduling, calendars, and customer booking workflows. It is commonly used by businesses to allow clients to reserve appointments or services directly on their site through a customer-facing interface.

What does arbitrary shortcode execution mean for CVE-2026-92966?

This vulnerability falls under the weakness class of Improper Control of Generation of Code (CWE-94). It means the plugin fails to sanitize input, allowing an attacker to inject and run unauthorized WordPress shortcodes. Because the system treats these injected strings as legitimate instructions, it may inadvertently perform actions or access data the attacker should not control.

How is this vulnerability triggered?

An attacker initiates the bug by entering a malicious shortcode into a name field during the plugin's public booking process. Simply visiting the site does not trigger the issue; the malicious payload must be submitted. The code only executes later, when an administrator or user views the Customer Cabinet block, causing the system to process and run the stored malicious input.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin, your risk is elevated because LatePoint is designed to be internet-facing to handle public bookings. Halo Surface Signal identifies this as an external risk because the booking flow must be accessible to the public to function, providing a direct path for unauthenticated users to interact with the vulnerable code component.

What should I do if I use LatePoint on my WordPress site?

Your priority is to identify every WordPress instance in your environment where this plugin is active. Once identified, evaluate if the site is reachable from the internet and determine its importance to your operations. Coordinate with your team to review the plugin status and prepare to apply updates or implement alternative security measures to mitigate the risk of unauthorized execution.

References