CVE-2026-92966 is an arbitrary WordPress shortcode-execution vulnerability in the LatePoint appointment booking plugin through version 5.7.0. Insufficient validation permits shortcode-bearing input to be stored during the booking flow. When the Customer Cabinet block subsequently renders the stored customer name through render_customer_dashboard(), WordPress reparses the output with its do_shortcode filter and executes the embedded shortcode.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is an operational Python PoC for the claimed CVE-2026-92966 affecting the WordPress LatePoint Appointment Booking plugin through version 5.7.0. poc.py is the CLI entry point: it supports interactive operation, single-target checking/exploitation, multithreaded target-list processing, optional force/verbose settings, custom shortcode injection, and a local lab. _engine.py contains the substantive HTTP logic, target normalization, LatePoint version detection, booking-flow interaction, customer-session/dashboard triggering, result metadata, and a local HTTP lab. The default mode is exploitation rather than detection-only. The exploit fingerprints target-relative LatePoint readme and plugin files, then uses WordPress admin-ajax.php and the public LatePoint route-call booking mechanism to store a caption shortcode marker in customer name data. It verifies exploitation only when that marker appears after loading a Customer Cabinet/dashboard context. targets.example.txt supplies an example URL list, while up.php is an optional standalone marker probe for use only if an external custom shortcode chain writes files. The repository does not contain a built-in OS command shell, file upload, or direct RCE payload; its claimed RCE impact depends on an additional target-specific shortcode gadget supplied by the operator.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical arbitrary WordPress shortcode-execution vulnerability caused by insufficient validation of user-supplied values in the LatePoint Appointment Booking Plugin. An authenticated user with Subscriber-level privileges or above could exploit it.
An unauthenticated arbitrary shortcode-execution vulnerability (CWE-94) in the LatePoint WordPress appointment-booking plugin through version 5.7.0. A malicious shortcode may be stored through the public booking workflow and later executed when the Customer Cabinet dashboard renders the stored customer name. The listed CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.