# Appointment Booking Plugin <= 5.7.3 - Unauthenticated Sensitive Information Exposure via Template Variable Injection in Customer Name and Notes

- **ID:** WPSEC-2026-0452
- **Plugin:** Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress (`latepoint`), https://wordpress.org/plugins/latepoint/
- **Affected versions:** all versions before 5.7.4
- **Fixed in:** 5.7.4 (Update to 5.7.4 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-1336
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/latepoint
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0452/

## Description

The LatePoint plugin for WordPress is vulnerable to Sensitive Information Exposure via template variable injection in all versions up to, and including, 5.7.3. This is due to customer-supplied first name, last name and notes being substituted into notification templates without neutralizing the {{ }} placeholder delimiters, so that placeholders contained in them are expanded by later replacement passes. This makes it possible for unauthenticated attackers who make a booking to place template variables in their details and have them expanded in the notifications sent to them, exposing the assigned agent's email address, phone number and additional contact details, as well as the internal admin notes kept on their customer record.

## References

- https://wpsec.com/vuln/WPSEC-2026-0452/
- https://plugins.svn.wordpress.org/latepoint/tags/5.7.4/
- https://wordpress.org/plugins/latepoint/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0452/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
