Appointment Booking Plugin <= 5.7.3 - Unauthenticated Sensitive Information Exposure via Template Variable Injection in Customer Name and Notes

Medium 5.3 CWE-1336Fixed in 5.7.4
ID
WPSEC-2026-0452
Plugin
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (latepoint)
Affected
all versions before 5.7.4
Remediation
Update to 5.7.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-1336
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Appointment Booking Plugin on WPSec AttackSurface
Fix released
Published

Description

The LatePoint plugin for WordPress is vulnerable to Sensitive Information Exposure via template variable injection in all versions up to, and including, 5.7.3. This is due to customer-supplied first name, last name and notes being substituted into notification templates without neutralizing the {{ }} placeholder delimiters, so that placeholders contained in them are expanded by later replacement passes. This makes it possible for unauthenticated attackers who make a booking to place template variables in their details and have them expanded in the notifications sent to them, exposing the assigned agent's email address, phone number and additional contact details, as well as the internal admin notes kept on their customer record.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0