Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Latepoint
Latepoint latepoint – Calendar Booking Plugin For Appointments And Events Wordpress Wordpress wordpress |
|
| Vendors & Products |
Latepoint
Latepoint latepoint – Calendar Booking Plugin For Appointments And Events Wordpress Wordpress wordpress |
Thu, 14 May 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() function. This makes it possible for unauthenticated attackers to cancel a logged-in customer's bookings via a forged request, granted they can trick the customer into performing an action such as clicking on a link. | |
| Title | LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-14T10:44:28.705Z
Reserved: 2026-04-01T18:03:07.898Z
Link: CVE-2026-5365
Updated: 2026-05-14T10:44:24.153Z
Status : Deferred
Published: 2026-05-14T07:16:20.110
Modified: 2026-05-14T14:28:41.283
Link: CVE-2026-5365
No data.
OpenCVE Enrichment
Updated: 2026-05-14T08:30:16Z