CVE-2026-11866
Deferred Deferred - Pending Action

Appointment Booking Plugin CSRF to Privilege Escalation

Vulnerability report for CVE-2026-11866, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-16

Last updated on: 2026-07-16

Assigner: WPScan

Description

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-16
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
appointment_booking_plugin appointment_booking_plugin to 5.6.3 (exc)
latepoint latepoint to 5.6.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin LatePoint versions before 5.6.3. It allows attackers to perform privileged actions via Cross-Site Request Forgery (CSRF) due to missing CSRF nonce validation. An attacker can trick a logged-in administrator into executing actions like modifying booking-form settings or disconnecting payment gateways by hosting a malicious webpage.

Detection Guidance

To detect this vulnerability, check the installed version of the LatePoint plugin in your WordPress site. If the version is below 5.6.3, the system is vulnerable. You can verify the version via the WordPress admin panel under Plugins or by inspecting the plugin files on the server.

Impact Analysis

An attacker could overwrite booking-form configurations, such as disabling required fields like email, or disconnect payment gateways. This could disrupt booking services, compromise payment processing, or lead to unauthorized changes in plugin settings without the administrator's knowledge.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized modifications to booking forms or payment gateway settings. An attacker could disable required fields in forms, potentially violating data collection or security requirements under these regulations. For GDPR, this might affect consent mechanisms or data minimization principles, while for HIPAA, it could compromise protected health information handling.

Mitigation Strategies

Immediately update the LatePoint plugin to version 5.6.3 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review plugin settings for unauthorized changes, especially in booking forms and payment gateway configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11866. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart