Skip to main content

CVE-2025-6815: LatePoint WordPress Plugin XSS Vulnerability

CVE-2025-6815 is a stored XSS vulnerability in LatePoint Calendar Booking Plugin for WordPress affecting versions up to 5.1.94. Attackers with admin access can inject malicious scripts via service parameters. This article covers technical details, affected installations, impact assessment, and mitigation strategies.

Published:

CVE-2025-6815 Overview

CVE-2025-6815 is a Stored Cross-Site Scripting (XSS) vulnerability in the LatePoint – Calendar Booking Plugin for Appointments and Events for WordPress. The flaw affects all plugin versions up to and including 5.1.94. It stems from insufficient input sanitization and output escaping on the service[name] parameter. Authenticated attackers with administrator-level access can inject arbitrary web scripts that execute when any user views an affected page. The issue is scoped to multi-site installations and installations where the unfiltered_html capability has been disabled. The weakness is tracked under CWE-79.

Critical Impact

An authenticated administrator on a WordPress multi-site can inject persistent JavaScript via the LatePoint service name field, enabling session hijacking or privilege actions against super admins who view the page.

Affected Products

  • LatePoint – Calendar Booking Plugin for Appointments and Events (WordPress plugin)
  • All versions up to and including 5.1.94
  • WordPress multi-site installations, or installations where unfiltered_html has been disabled

Discovery Timeline

  • 2025-09-30 - CVE-2025-6815 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6815

Vulnerability Analysis

The LatePoint plugin accepts a service[name] value when administrators create or edit a bookable service. The plugin stores this value in the database and later renders it in pages served to site users and other administrators. The rendering path does not apply sufficient output escaping, and the input path does not strip executable markup. An administrator can submit a payload containing <script> tags or event-handler attributes, which the plugin stores verbatim and emits into the HTML response.

On standard single-site WordPress installations, administrators already hold the unfiltered_html capability, so this class of injection is considered expected behavior. The vulnerability becomes security-relevant on multi-site networks, where only super admins hold unfiltered_html, and on hardened installations where the capability has been explicitly revoked. In those contexts, a site administrator who should not be able to introduce raw HTML can achieve persistent script execution against higher-privileged users.

Root Cause

The root cause is missing sanitization of the service[name] input before persistence and missing contextual output escaping when the stored value is rendered. The plugin trusts administrator-supplied input and does not enforce the WordPress capability boundary that unfiltered_html is designed to represent.

Attack Vector

Exploitation requires an authenticated account with administrator privileges on the target site. The attacker edits a LatePoint service and places a JavaScript payload inside the service name field. When any user, including a super admin, visits a page that renders the service name, the injected script executes in the victim's browser session. This can be chained to perform actions as the victim, exfiltrate authentication cookies accessible to JavaScript, or pivot to actions requiring higher privileges than the attacker holds.

No verified public proof-of-concept code is available. See the Wordfence Vulnerability Analysis for additional technical context.

Detection Methods for CVE-2025-6815

Indicators of Compromise

  • LatePoint service records whose name field contains <script>, onerror=, onload=, javascript:, or encoded variants.
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains when viewing LatePoint pages.
  • New or modified WordPress administrator accounts, API keys, or application passwords created shortly after a super admin visited a LatePoint page.
  • Database rows in LatePoint service tables modified by a lower-privileged administrator account outside normal change windows.

Detection Strategies

  • Query the LatePoint services table for HTML metacharacters or script-related tokens in the name column.
  • Monitor WordPress audit logs for service create or update events performed by non-super-admin administrators on multi-site networks.
  • Inspect HTTP responses from LatePoint admin and front-end pages for unescaped markup originating from stored service names.

Monitoring Recommendations

  • Centralize WordPress and web server logs in a SIEM and alert on admin-area POSTs to LatePoint endpoints followed by anomalous script retrievals.
  • Track plugin version inventory across WordPress sites and flag any instance running LatePoint 5.1.94 or earlier.
  • Alert on new WordPress administrator or super admin accounts created within a short window of a LatePoint service edit.

How to Mitigate CVE-2025-6815

Immediate Actions Required

  • Update the LatePoint plugin to the version published after 5.1.94 that remediates this issue, as documented in the WordPress Plugin Changeset.
  • Audit all LatePoint service records for stored script payloads and sanitize or remove malicious entries.
  • Review administrator accounts on multi-site networks and revoke access that is no longer required.
  • Rotate session cookies, application passwords, and API keys for any super admin who viewed LatePoint pages while a suspicious service name was stored.

Patch Information

The vendor addressed the vulnerability in a release following version 5.1.94. Review the WordPress Plugin Changeset and the WordPress LatePoint Plugin Overview page to confirm the fixed version and upgrade all affected sites.

Workarounds

  • Restrict LatePoint administrative access to trusted super admins only until the plugin is upgraded.
  • Deploy a web application firewall rule that blocks HTML and script tokens in the service[name] request parameter.
  • Enforce a strict Content Security Policy that disallows inline scripts on WordPress admin and booking pages to limit the impact of stored payloads.
bash
# Configuration example: upgrade the LatePoint plugin via WP-CLI
wp plugin update latepoint --version=latest
wp plugin get latepoint --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.