PT-2026-103673 · WordPress · Latepoint

·

CVE-2026-92966

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions LatePoint versions prior to 5.7.1
Description An issue allows unauthenticated attackers to execute arbitrary shortcodes. This occurs because the software fails to properly validate a value before it is processed by the do shortcode function. The payload is introduced during the unauthenticated booking process and is triggered when the render customer dashboard() function outputs the stored name into the content stream, causing the WordPress core do shortcode filter to re-parse and execute it.
Recommendations Update to a version newer than 5.7.0.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92966

Affected Products

Latepoint