POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
← Blog

LatePoint Stored Shortcodes (CVE-2026-92966): Booking Names and Customer Cabinet

Admin · October 1, 2026 · 3 views

LatePoint and the double do_shortcode trap

LatePoint is a popular WordPress appointment booking plugin. CVE-2026-92966 (Wordfence CNA, CVSS 3.1 9.1 Critical, CWE-94) is unauthenticated stored shortcode execution in ≤ 5.7.0, fixed in 5.7.1.

The bug is not “RCE in one HTTP request” on every site—it is a reliable two-step chain:

  1. Plant — Anonymous booking stores customer first name / last name with only sanitize_text_field(), which does not strip [ and ], so values like [caption]…[/caption] persist in the database.
  2. Trigger — A page with the Customer Cabinet Gutenberg block renders a welcome line containing the customer name. WordPress runs do_shortcode on the_content at priority 11, so shortcodes embedded in that HTML get a second parse pass and execute.

5.7.1 fixes output with encode_shortcode_delimiters() on dashboard HTML (see vendor comment in shortcodes_helper.php about priority-11 do_shortcode).

Public mechanism and lab tooling: CVE-2026-92966 on pocbit.org. Repository: murrez/CVE-2026-92966.

Why esc_html did not save you

Developers often assume esc_html() on user display names neutralizes injection. Here the payload is not HTML—it is shortcode syntax. Brackets survive encoding, survive storage, and become active when WordPress’s shortcode engine runs again on block output.

Impact is arbitrary shortcode execution. On a typical stack that may chain to critical plugins (forms, builders, file managers, or other eval‑backed shortcodes). The PoC proves execution with core [caption] and marker POCBIT-92966-OK; site-specific gadgets use POCBIT_EXEC_SHORTCODE in authorized tests.

Defender checklist

| # | Action | Detail | |---|--------|--------| | 1 | Confirm LatePoint version | readme.txt stable tag under /wp-content/plugins/latepoint/ | | 2 | Upgrade to ≥ 5.7.1 immediately | Verify encode_shortcode_delimiters on customer dashboard output | | 3 | Audit customer records for [ / ] in names | Post-patch hygiene | | 4 | Review Customer Cabinet block placement | Any public page with the block + guest booking increases trigger surface | | 5 | If booking is not needed, restrict public wizard | Reduces planting | | 6 | Temporary WAF | Block brackets in customer[first_name] / last_name on latepoint_route_call—bridge only |

Cross-read: WordPress plugin vulnerabilities defender guide, WordPress security checklist (2026), WAF rules for WordPress emergencies.

Mass-scan reality (blue team expectations)

Exploit automation reports statuses such as plant_no_auth_cookie, plant_missing_service_id, no_customer_cabinet_page, and shortcode_not_triggered. Real-world success depends on:

  • Public booking reachable without payment blockers
  • At least one published Customer Cabinet page
  • Guest session after booking (or login) to load the dashboard

Check mode still helps you find ≤ 5.7.0 assets before opportunistic spray.

Detection hints (your assets only)

body="/wp-content/plugins/latepoint/"
body="latepoint-book-form"
body="latepoint_helper"

Patch validation in a lab

  1. Install LatePoint 5.7.0 on a disposable WordPress site with booking + Customer Cabinet block.
  2. Run public PoC check mode, then controlled exploit in the lab.
  3. Upgrade to 5.7.1; repeat—expect patched skip or no second-pass execution.

See safe PoC lab setup and CVE PoC testing step-by-step.

FAQ

Is this full OS RCE out of the box?

Not guaranteed on every site. The CVE is shortcode execution; critical impact often requires a dangerous shortcode from another extension. Still patch—attackers inventory stacks.

Can we strip brackets at the WAF forever?

Only as a temporary control. Booking forms legitimately rarely need [ in names; vendor encoding is the durable fix.

Does disabling the block help?

Removing Customer Cabinet from public pages reduces trigger paths but leaves stored payloads in the DB. Upgrade plus name audit is the correct response.

Bottom line

CVE-2026-92966 teaches that WordPress shortcodes are code, and the_content filters can re-parse HTML you thought was “escaped.” Upgrade LatePoint to 5.7.1+, audit customer names, and treat booking plugins as part of your plugin supply-chain review—not passive background noise.