PT-2026-68471 · WordPress · Latepoint
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LatePoint versions prior to 5.3.3
Description
Stored Cross-Site Scripting occurs when authenticated attackers with contributor level access or higher inject arbitrary web scripts into pages. This issue stems from insufficient input sanitization and output escaping within the
locations branch of the shortcode latepoint resources() function, specifically affecting the btn wrapper classes attribute of the latepoint resources shortcode.Recommendations
Update LatePoint to a version newer than 5.3.2.
As a temporary mitigation, restrict the ability of users with contributor level access to edit pages or use the
latepoint resources shortcode.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint