WordPress Plugin Vulnerabilities

LatePoint < 5.4.1 - Unauthenticated Payment Bypass via Client-Supplied Stripe PaymentIntent ID

Description

The plugin is vulnerable to a payment amount-binding bypass. Its Stripe Connect payment processor accepts a client-supplied PaymentIntent ID, making it possible for unauthenticated attackers to complete a booking for an arbitrary amount by supplying a previously succeeded PaymentIntent token instead of paying the intended price.

Affects Plugins

Fixed in 5.4.1

References

Miscellaneous

Original Researcher
Andrés Cruciani
Verified
No

Timeline

Publicly Published
2026-07-07 (about 1 month ago)
Added
2026-07-08 (about 1 month ago)
Last Updated
2026-07-08 (about 1 month ago)

Other