Appointment Booking Plugin <= 5.7.3 - Unauthenticated Sensitive Information Exposure via Template Variable Injection in Customer Name and Notes
- ID
- WPSEC-2026-0452
- Plugin
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (latepoint)
- Affected
- all versions before 5.7.4
- Remediation
- Update to 5.7.4 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-1336
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Appointment Booking Plugin on WPSec AttackSurface
- Fix released
- Published
Description
The LatePoint plugin for WordPress is vulnerable to Sensitive Information Exposure via template variable injection in all versions up to, and including, 5.7.3. This is due to customer-supplied first name, last name and notes being substituted into notification templates without neutralizing the {{ }} placeholder delimiters, so that placeholders contained in them are expanded by later replacement passes. This makes it possible for unauthenticated attackers who make a booking to place template variables in their details and have them expanded in the notifications sent to them, exposing the assigned agent's email address, phone number and additional contact details, as well as the internal admin notes kept on their customer record.
References
- https://wpsec.com/vuln/WPSEC-2026-0452/
- https://plugins.svn.wordpress.org/latepoint/tags/5.7.4/
- https://wordpress.org/plugins/latepoint/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS