WordPress Plugin Vulnerabilities
LatePoint < 5.4.1 - Unauthenticated Payment Bypass via Client-Supplied Stripe PaymentIntent ID
Description
The plugin is vulnerable to a payment amount-binding bypass. Its Stripe Connect payment processor accepts a client-supplied PaymentIntent ID, making it possible for unauthenticated attackers to complete a booking for an arbitrary amount by supplying a previously succeeded PaymentIntent token instead of paying the intended price.
Affects Plugins
References
Miscellaneous
Original Researcher
Andrés Cruciani
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-07 (about 1 month ago)
Added
2026-07-08 (about 1 month ago)
Last Updated
2026-07-08 (about 1 month ago)