
LatePoint – Calendar Booking Plugin for Appointments and Events Security & Risk Analysis
wordpress.org/plugins/latepointOptimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
Is LatePoint – Calendar Booking Plugin for Appointments and Events Safe to Use in 2026?
Critical Risk — Avoid
Score 20/100LatePoint – Calendar Booking Plugin for Appointments and Events is critically unsafe with 18 known CVEs, 2 still unpatched. Avoid in production.
The security posture of the LatePoint plugin version 5.2.11 presents significant concerns. While the static analysis indicates a lack of immediately critical "dangerous functions" or taint flows, several factors point to a weak security foundation. The plugin has a substantial history of vulnerabilities, with 18 known CVEs, including 4 critical and 4 high-severity issues. The fact that 2 CVEs remain unpatched is a major red flag, suggesting active threats could exploit these known weaknesses. The recent vulnerability date (2026-03-10) is also concerning, indicating ongoing security issues. Furthermore, the static analysis reveals 2 unprotected AJAX handlers, representing a direct entry point for attackers without proper authentication. The lack of any output escaping (0% properly escaped) across 13 outputs is a critical vulnerability for Cross-Site Scripting (XSS), allowing attackers to inject malicious scripts into the website. The absence of nonce checks and capability checks on potentially sensitive operations further exacerbates these risks. While the plugin uses prepared statements for most SQL queries, the overall pattern of historical vulnerabilities and critical static analysis findings (unescaped output, unprotected entry points) outweighs the strengths.
Key Concerns
- Unpatched CVEs present
- Critical vulnerability in output escaping
- Unprotected AJAX handlers
- Missing nonce checks
- Missing capability checks
- High number of historical vulnerabilities
LatePoint – Calendar Booking Plugin for Appointments and Events Security Vulnerabilities
CVEs by Year
Severity Breakdown
18 total CVEs
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting
LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import
LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting
LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function
LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function
LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting
LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion
Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference
LatePoint <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
LatePoint <= 5.0.12 - Authentication Bypass
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting
LatePoint <= 4.9.91 - Cross-Site Request Forgery
LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR
LatePoint – Calendar Booking Plugin for Appointments and Events Code Analysis
SQL Query Safety
Output Escaping
LatePoint – Calendar Booking Plugin for Appointments and Events Attack Surface
AJAX Handlers 2
Shortcodes 6
WordPress Hooks 44
Scheduled Events 2
Maintenance & Trust
LatePoint – Calendar Booking Plugin for Appointments and Events Maintenance & Trust
Maintenance Signals
Community Trust
LatePoint – Calendar Booking Plugin for Appointments and Events Alternatives
Cal24h
cal24h
Embed the Cal24h booking experience in WordPress with a shortcode, Gutenberg block, or floating modal.
NiftyBukzee – Calendar Booking Plugin for Appointments and Events
niftybukzee
Gain More customers with Quick and Easy 3-step appointment booking with service providers: Calendar, Payments, Google Meet & more.
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Booking Calendar
booking
Original "Booking Calendar" plugin. Easily manage full-day bookings, time-slot appointments, or events in our all-in-one, outstanding booking system.
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
LatePoint – Calendar Booking Plugin for Appointments and Events Developer Profile
1 plugin · 100K total installs
How We Detect LatePoint – Calendar Booking Plugin for Appointments and Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/latepoint/public/stylesheets/frontend.css/wp-content/plugins/latepoint/public/stylesheets/frontend_booking_form.css/wp-content/plugins/latepoint/public/stylesheets/frontend_booking_form_responsive.css/wp-content/plugins/latepoint/public/javascripts/frontend.js/wp-content/plugins/latepoint/public/javascripts/vendor/moment.min.js/wp-content/plugins/latepoint/public/javascripts/vendor/moment_timezone.min.js/wp-content/plugins/latepoint/public/javascripts/vendor/fullcalendar.min.js/wp-content/plugins/latepoint/public/javascripts/vendor/vue.js+4 more/wp-content/plugins/latepoint/public/javascripts/frontend.jslatepoint/public/stylesheets/frontend.css?ver=latepoint/public/javascripts/frontend.js?ver=HTML / DOM Fingerprints
latepoint-booking-formlp-booking-form-wrapperlp-booking-form-steplp-booking-form-agent-selectionlp-booking-form-service-selectionlp-booking-form-date-selectionlp-booking-form-time-selectionlp-booking-form-summary+9 more<!-- LatePoint booking form start --><!-- LatePoint booking form end --><!-- LatePoint calendar start --><!-- LatePoint calendar end -->data-latepoint-booking-formdata-lp-booking-formdata-lp-agent-iddata-lp-service-iddata-lp-stepdata-lp-date+2 moreLatePointBookingFormLatePointFrontendLatePointCalendar/wp-json/latepoint/v1/booking/prepare/wp-json/latepoint/v1/booking/create/wp-json/latepoint/v1/agents/wp-json/latepoint/v1/services/wp-json/latepoint/v1/availability/wp-json/latepoint/v1/payment/process/wp-json/latepoint/v1/customers[latepoint_booking_form][latepoint_calendar][latepoint_agent_dashboard][latepoint_customer_dashboard]