WordPress · Latepoint · CVE-2026-92966
**Name of the Vulnerable Software and Affected Versions**
LatePoint versions prior to 5.7.1
**Description**
An issue allows unauthenticated attackers to execute arbitrary shortcodes. This occurs because the software fails to properly validate a value before it is processed by the `do shortcode` function. The payload is introduced during the unauthenticated booking process and is triggered when the `render customer dashboard()` function outputs the stored name into the content stream, causing the WordPress core `do shortcode` filter to re-parse and execute it.
**Recommendations**
Update to a version newer than 5.7.0.