Mmastodon TechnologyCybersecurity first seen 17 h ago, last 17 h ago, peak #4
Widely used WordPress booking plugin LatePoint hit by security flaw
Original: LatePoint, a WordPress booking plugin on 100,000+ sites, has a flaw: any logged-in user can rewrite every customer's ema
LatePoint, a WordPress booking plugin installed on more than 100,000 websites, contains a vulnerability tracked as CVE-2026-17538. Any logged-in user can change the email address and phone number of every customer, and sites with open registration make this reachable by anyone. A related setting can escalate the flaw to full account takeover. Administrators are urged to update to version 5.7.4, which fixes the issue.
Why now: Security researchers are warning site administrators to patch quickly because the flaw is trivially exploitable on sites with open sign-up.
LatePointWordPressCVE-2026-17538
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1421659