
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Security & Risk Analysis
wordpress.org/plugins/latepointAppointment booking plugin for WordPress. Let clients self-schedule 24/7, accept payments at booking, and reduce no-shows, all from your WordPress sit …
Is Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Safe to Use in 2026?
Critical Risk — Avoid
Score 20/100Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress is critically unsafe with 35 known CVEs, 2 still unpatched. Avoid in production.
The security posture of the LatePoint plugin version 5.2.11 presents significant concerns. While the static analysis indicates a lack of immediately critical "dangerous functions" or taint flows, several factors point to a weak security foundation. The plugin has a substantial history of vulnerabilities, with 18 known CVEs, including 4 critical and 4 high-severity issues. The fact that 2 CVEs remain unpatched is a major red flag, suggesting active threats could exploit these known weaknesses. The recent vulnerability date (2026-03-10) is also concerning, indicating ongoing security issues. Furthermore, the static analysis reveals 2 unprotected AJAX handlers, representing a direct entry point for attackers without proper authentication. The lack of any output escaping (0% properly escaped) across 13 outputs is a critical vulnerability for Cross-Site Scripting (XSS), allowing attackers to inject malicious scripts into the website. The absence of nonce checks and capability checks on potentially sensitive operations further exacerbates these risks. While the plugin uses prepared statements for most SQL queries, the overall pattern of historical vulnerabilities and critical static analysis findings (unescaped output, unprotected entry points) outweighs the strengths.
Key Concerns
- Unpatched CVEs present
- Critical vulnerability in output escaping
- Unprotected AJAX handlers
- Missing nonce checks
- Missing capability checks
- High number of historical vulnerabilities
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
35 total CVEs
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.3 - Unauthenticated SQL Injection
LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset
LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege Escalation
LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route
LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting
LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter
LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object Reference
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting
LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import
LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting
LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function
LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function
LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting
LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion
Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference
LatePoint <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
LatePoint <= 5.0.12 - Authentication Bypass
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting
LatePoint <= 4.9.91 - Cross-Site Request Forgery
LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Release Timeline
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Code Analysis
SQL Query Safety
Output Escaping
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Attack Surface
AJAX Handlers 2
Shortcodes 6
WordPress Hooks 44
Scheduled Events 2
Maintenance & Trust
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Alternatives
Simply Schedule Appointments
simply-schedule-appointments
Unlimited appointments, booking calendars, and notifications. Powerful appointment booking plugin and booking system. Start scheduling for free today!
WPS Bookings for WooCommerce
mwb-bookings-for-woocommerce
This WordPress Booking Plugin lets you manage full-day bookings, service appointments, Accept/reject bookings, show booking availability & much more.
Advanced Appointment Booking & Scheduling
advanced-appointment-booking-scheduling
Advanced Appointment Booking & Scheduling: Effortlessly manage appointments with a simple, user-friendly scheduling system.
Bookify – Appointment Booking & Scheduling for WordPress
bookify
🚀 A modern, lightweight appointment booking plugin for WordPress. Let customers book services online, manage schedules easily, and reduce no-shows — n …
Online Booking & Appointment Scheduling – Vigore
bookme-widget
Add online booking and appointment scheduling to WordPress with a free Vigore account. Take payments, send reminders and sync your calendar.
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Developer Profile
1 plugin · 100K total installs
How We Detect Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/latepoint/public/stylesheets/frontend.css/wp-content/plugins/latepoint/public/stylesheets/frontend_booking_form.css/wp-content/plugins/latepoint/public/stylesheets/frontend_booking_form_responsive.css/wp-content/plugins/latepoint/public/javascripts/frontend.js/wp-content/plugins/latepoint/public/javascripts/vendor/moment.min.js/wp-content/plugins/latepoint/public/javascripts/vendor/moment_timezone.min.js/wp-content/plugins/latepoint/public/javascripts/vendor/fullcalendar.min.js/wp-content/plugins/latepoint/public/javascripts/vendor/vue.js+4 more/wp-content/plugins/latepoint/public/javascripts/frontend.jslatepoint/public/stylesheets/frontend.css?ver=latepoint/public/javascripts/frontend.js?ver=HTML / DOM Fingerprints
latepoint-booking-formlp-booking-form-wrapperlp-booking-form-steplp-booking-form-agent-selectionlp-booking-form-service-selectionlp-booking-form-date-selectionlp-booking-form-time-selectionlp-booking-form-summary+9 more<!-- LatePoint booking form start --><!-- LatePoint booking form end --><!-- LatePoint calendar start --><!-- LatePoint calendar end -->data-latepoint-booking-formdata-lp-booking-formdata-lp-agent-iddata-lp-service-iddata-lp-stepdata-lp-date+2 moreLatePointBookingFormLatePointFrontendLatePointCalendar/wp-json/latepoint/v1/booking/prepare/wp-json/latepoint/v1/booking/create/wp-json/latepoint/v1/agents/wp-json/latepoint/v1/services/wp-json/latepoint/v1/availability/wp-json/latepoint/v1/payment/process/wp-json/latepoint/v1/customers[latepoint_booking_form][latepoint_calendar][latepoint_agent_dashboard][latepoint_customer_dashboard]