MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #4

Widely used WordPress booking plugin LatePoint hit by security flaw

Original: LatePoint, a WordPress booking plugin on 100,000+ sites, has a flaw: any logged-in user can rewrite every customer's ema

LatePoint, a WordPress booking plugin installed on more than 100,000 websites, contains a vulnerability tracked as CVE-2026-17538. Any logged-in user can change the email address and phone number of every customer, and sites with open registration make this reachable by anyone. A related setting can escalate the flaw to full account takeover. Administrators are urged to update to version 5.7.4, which fixes the issue.

Why now: Security researchers are warning site administrators to patch quickly because the flaw is trivially exploitable on sites with open sign-up.

LatePointWordPressCVE-2026-17538

Open on mastodon →

Rank over time, top of the chart is #1. 2 snapshots from 8 h ago to 8 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1421659