Medium severity4.3NVD Advisory· Published May 14, 2026· Updated Jun 17, 2026
CVE-2026-5365
CVE-2026-5365
Description
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() function. This makes it possible for unauthenticated attackers to cancel a logged-in customer's bookings via a forged request, granted they can trick the customer into performing an action such as clicking on a link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=5.3.2+ 1 more
- (no CPE)range: <=5.3.2
- (no CPE)
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.