WordPress · Latepoint · CVE-2026-5391
**Name of the Vulnerable Software and Affected Versions**
LatePoint versions prior to 5.3.3
**Description**
Stored Cross-Site Scripting occurs when authenticated attackers with contributor level access or higher inject arbitrary web scripts into pages. This issue stems from insufficient input sanitization and output escaping within the `locations` branch of the `shortcode latepoint resources()` function, specifically affecting the `btn wrapper classes` attribute of the `latepoint resources` shortcode.
**Recommendations**
Update LatePoint to a version newer than 5.3.2.
As a temporary mitigation, restrict the ability of users with contributor level access to edit pages or use the `latepoint resources` shortcode.