Input validation vulnerability in LatePoint – Calendar Booking Plugin for Appointments and Events 5.2.7

The LatePoint plugin, used for booking appointments and events on the WordPress platform, has a security vulnerability that allows hackers to inject harmful code through the JSON Import feature. This can happen in all versions of the plugin up to version 5.2.7. The issue arises from the lack of proper checks on the JSON data provided by users. This means that attackers with high-level access can run unauthorized SQL queries on the website’s database, potentially stealing information, causing damage, or making changes.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.