PT-2026-103673 · WordPress · Latepoint
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LatePoint versions prior to 5.7.1
Description
An issue allows unauthenticated attackers to execute arbitrary shortcodes. This occurs because the software fails to properly validate a value before it is processed by the
do shortcode function. The payload is introduced during the unauthenticated booking process and is triggered when the render customer dashboard() function outputs the stored name into the content stream, causing the WordPress core do shortcode filter to re-parse and execute it.Recommendations
Update to a version newer than 5.7.0.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint