{
 "id": "WPSEC-2026-0452",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0452/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0452/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0452/index.md",
 "title": "Appointment Booking Plugin <= 5.7.3 - Unauthenticated Sensitive Information Exposure via Template Variable Injection in Customer Name and Notes",
 "description": "The LatePoint plugin for WordPress is vulnerable to Sensitive Information Exposure via template variable injection in all versions up to, and including, 5.7.3. This is due to customer-supplied first name, last name and notes being substituted into notification templates without neutralizing the {{ }} placeholder delimiters, so that placeholders contained in them are expanded by later replacement passes. This makes it possible for unauthenticated attackers who make a booking to place template variables in their details and have them expanded in the notifications sent to them, exposing the assigned agent's email address, phone number and additional contact details, as well as the internal admin notes kept on their customer record.",
 "plugin": {
  "slug": "latepoint",
  "name": "Appointment Booking Plugin",
  "full_name": "Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/latepoint/",
  "advisories_url": "https://wpsec.com/vuln/plugin/latepoint/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/latepoint"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-1336"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.7.4",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.7.4"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.7.4",
 "remediation": "Update to 5.7.4 or later.",
 "fix_released": "2026-10-05T10:44:07+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:12.979662+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0452/",
  "https://plugins.svn.wordpress.org/latepoint/tags/5.7.4/",
  "https://wordpress.org/plugins/latepoint/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/latepoint",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}