CVE-2025-7038

Published
View on NVD ↗
CVSS v3
8.2
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in all versions up to, and including, 5.1.94. The endpoint reads the client-supplied customer email and related customer fields before invoking the internal login handler without verifying login status, capability checks, or a valid AJAX nonce. This makes it possible for unauthenticated attackers to log into any customer’s account.

<p><strong>LatePoint – The Lightweight Appointment Booking Plugin for WordPress</strong></p> <p><strong>★★★★★</strong></p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/s5lcrXFWQcw?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p><a href="https://latepoint.com/changelog/?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">What&#8217;s New</a> | <a href="https://wpdocs.latepoint.com/?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">Docs</a> | <a href="https://www.youtube.com/watch?v=wwQ5EwEln6E&amp;utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">Video Tutorial</a> | <a href="https://wpdocs.latepoint.com/support/?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">Get Help</a></p> <p>LatePoint is a simple yet lightweight and powerful appointment booking plugin for WordPress. Built for service-based businesses, it helps your customers book appointments in just a few clicks, without the back-and-forth emails or clunky booking systems.</p> <p>Whether you&#8217;re a coach, salon, consultant, or clinic, if your business runs on bookings, LatePoint makes it easy to manage your schedule, take payments, and let clients book online 24/7.</p> <p>Set it up in 10 minutes. Look professional. Automate the boring stuff. Let LatePoint handle the heavy lifting so you can focus on your business.</p> <p><a href="https://app.zipwp.com/blueprint/latepoint-demo-m00?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">Try the Live Demo</a></p> <h3>What You Can Do With LatePoint</h3> <ul> <li>Let customers book appointments online 24/7</li> <li>Manage your calendar and availability with ease</li> <li>Accept payments with Stripe (Braintree, Flutterwave, MercadoPago, Molie, PayPal, Paystack, RazorPay, Square, Woo, SureCart available in Pro)</li> <li>Sync with Google Calendar (Pro)</li> <li>Offer in-person or virtual sessions (Zoom/Google Meet with Pro)</li> <li>Support for multiple staff, services, and locations</li> <li>Send automatic confirmations and reminders</li> <li>Customize booking forms to collect the info you need</li> <li>Provide a customers dashboard to manage bookings (Pro)</li> <li>View and control everything from a unified admin dashboard</li> <li>Use coupons, addons, and follow-ups to boost engagement (Pro)</li> <li>Let customers book multiple appointments at once (Booking Cart &#8211; Pro)</li> </ul> <p><a href="https://wpastra.com/review/latepoint-review/?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">LatePoint Review: Is It the Right Booking Plugin for Your Service?</a></p> <h3>Who Is LatePoint For?</h3> <p>LatePoint is trusted by freelancers, studios, agencies, and small business owners across many industries. If your business runs on appointments, LatePoint can save you time and make your life easier.</p> <p><strong>Salons &amp; Studios</strong></p> <p>If you run a personal care studio, hair or nail salon, spa, massage therapist or tattoo studio, you&#8217;ll know how important it is to avoid no-shows, double-bookings, and awkward payment moments.</p> <p>With LatePoint:</p> <ul> <li>Customers can book online anytime</li> <li>You can send automatic reminders so clients actually show up</li> <li>Accept payments upfront or after the session</li> <li>Sync your bookings with Google Calendar</li> </ul> <p><a href="https://www.youtube.com/watch?v=IWbBoEyXklI&amp;utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">▶️ How To Set Up LatePoint for Salons</a></p> <p><strong>Coaches, Consultants &amp; Trainers</strong></p> <p>If you run 1:1 sessions, group coaching, or online workshops, LatePoint keeps your schedule organized and sessions full.</p> <ul> <li>Let clients pick time slots based on availability</li> <li>Offer in-person or Zoom sessions</li> <li>Sell service packages and recurring appointments</li> </ul> <p><strong>Clinics, Therapists &amp; Healthcare Pros</strong></p> <p>For medical, wellness, or therapy practices, LatePoint helps you stay professional while giving patients a smooth experience.</p> <ul> <li>Collect patient information with custom fields</li> <li>Offer multiple services with different specialists</li> <li>Manage multiple staff calendars and locations</li> </ul> <p><strong>Education &amp; Classes</strong></p> <p>Whether you&#8217;re a tutor, language teacher, or run in-person classes, you can:</p> <ul> <li>Let students book 1:1 or group sessions</li> <li>Limit bookings to your preferred hours</li> <li>Automate reminders and payments</li> </ul> <p><strong>Local Services &amp; Agencies</strong></p> <p>Photographers, cleaners, auto services, repair shops, if your business depends on appointments, LatePoint makes it simple.</p> <ul> <li>Show real-time availability</li> <li>Set different schedules by service or team member</li> <li>Let clients book 24/7, no calls or emails needed</li> </ul> <h3>What Makes LatePoint Unique?</h3> <p>LatePoint isn&#8217;t just another booking plugin, it&#8217;s designed to solve real-world scheduling problems with a smart, flexible approach.</p> <ul> <li><strong>Purpose-built for service providers:</strong> From solo pros to teams across locations, LatePoint adapts to your business.</li> <li><strong>Quick to launch, simple to manage:</strong> The built-in onboarding wizard walks you through the entire setup. You&#8217;ll go from install to taking bookings in under 10 minutes.</li> <li><strong>Mobile-first booking experience:</strong> Clients see clean, intuitive forms that work beautifully on phones, tablets, and desktops. Fewer clicks = fewer drop-offs.</li> <li><strong>Automation built-in:</strong> LatePoint handles confirmations, reminders, follow-ups, and payments. Skip the admin and focus on delivering your services.</li> <li><strong>Affordable, with a forever-free plan:</strong> You won&#8217;t get trapped in expensive subscriptions. Start with the free version, and upgrade when you need advanced features.</li> <li><strong>Native to WordPress:</strong> Built to feel like a natural part of your site, LatePoint works with most popular themes and page builders out of the box.</li> </ul> <h3>How It Works</h3> <ol> <li><strong>Install the plugin:</strong> Download LatePoint from the WordPress plugin repository and activate it on your site.</li> <li><strong>Complete the setup wizard:</strong> Walk through a simple onboarding process to set your timezone, services, staff, and availability.</li> <li><strong>Customize your booking form:</strong> Add custom fields to collect the information you need before a session. Choose which details to make required or optional.</li> <li><strong>Add booking to your site:</strong> Use a shortcode or LatePoint widget to place the booking interface into any page or post.</li> <li><strong>Start accepting bookings:</strong> Customers can now see your real-time availability, book appointments, pay (Pro), and receive confirmation emails.</li> <li><strong>Manage everything in your dashboard:</strong> View and manage appointments, customer information, payments, and notifications directly from your WordPress admin.</li> </ol> <p><a href="https://wpdocs.latepoint.com/getting-started-with-latepoint/?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">Follow the Step-by-Step Guide</a></p> <h3>Features You&#8217;ll Love</h3> <p>✅ <strong>Visual booking form builder</strong> &#8211; Customize steps, services, and fields without touching code<br /> ✅ <strong>Multi-step appointment scheduling</strong> &#8211; Clean, intuitive customer experience<br /> ✅ <strong>Multiple services, agents &amp; locations</strong> &#8211; Set schedules, prices, and availability per agent or location<br /> ✅ <strong>Customer dashboard</strong> &#8211; Customers can view and manage bookings, cancel and reschedule<br /> ✅ <strong>Admin dashboard</strong> &#8211; Full calendar view with filters for appointments, agents, and locations<br /> ✅ <strong>Google Calendar sync</strong> &#8211; Keep everything up to date across platforms<br /> ✅ <strong>Built-in notifications</strong> &#8211; Email, SMS, and WhatsApp notifications out of the box<br /> ✅ <strong>Online payments</strong> &#8211; Connect Stripe or PayPal to accept payments during booking<br /> ✅ <strong>Booking cart</strong> &#8211; Let customers book multiple appointments at once</p> <h3>Want To Unlock More?</h3> <p>LatePoint comes with a solid set of features in the free version, perfect if you&#8217;re just getting started. But if you&#8217;re managing multiple team members, need advanced scheduling logic, or want to offer online payments and video calls, the Pro version gives you that extra power.</p> <p>Here&#8217;s what you unlock with LatePoint Pro:</p> <ul> <li>Add unlimited agents and services</li> <li>Accept payments using other methods, such as PayPal</li> <li>Zoom and Google Meet integration</li> <li>Set up advanced availability rules and service durations</li> <li>Send custom reminders and follow-ups</li> <li>Support for deposits, coupons, and recurring bookings</li> </ul> <p><a href="https://docs.google.com/spreadsheets/d/1AcjnUEKGhM0ySAgm7ZKRt-PSqlJ05eZk1JiuL5ToGRs/edit?usp=sharing" rel="nofollow ugc">See the Full Free vs Pro Feature Comparison</a><br /> <a href="https://latepoint.com/pricing/?utm_source=wordpressorg&amp;utm_medium=plugin_listing&amp;utm_campaign=free_plugin" rel="nofollow ugc">Check Out LatePoint Pro</a></p> <h3>Works With Your Stack</h3> <ul> <li>Works with most Popular WordPress themes (Astra, Kadence, GeneratePress and others)</li> <li>Fully compatible with Elementor, Gutenberg, and page builders</li> <li>LatePoint is compatible with WooCommerce but doesn&#8217;t need it to work</li> <li>Extendable with official LatePoint add-ons (Zoom, WhatsApp, Packages, etc.)</li> </ul> <h3>Blocks</h3> <p>This plugin provides 6 blocks.</p> <ul> <li><strong>Customer dashboard:</strong> Adds a customer dashboard for LatePoint</li> <li><strong>Booking button:</strong> Adds a booking button</li> <li><strong>List of resources:</strong> Adds a list of bookable resources by type</li> <li><strong>Booking form:</strong> Adds a LatePoint booking form</li> <li><strong>Customer login:</strong> Adds a customer login form</li> <li><strong>Latepoint calendar:</strong> Adds a calendar of events</li> </ul> <h3>Trusted by 21,000+ Businesses</h3> <p>LatePoint has over 1,300 five-star reviews and is trusted by businesses worldwide, including the Nigerian Embassy, fitness chains, and solo freelancers.</p> <p>If you want a modern, effortless way to let your customers book online, give LatePoint a try today.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
1.16M