1 vulnerability across 1 product scored HIGH or above on October 01, 2026.
- π HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-09-28 bulletin.
- [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-26 bulletin.
- [UPGRADED] CVE-2026-93577 (gitlab/gitlab) β F1: exploitable β functional, AAS: 11.9 β 13.9 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
π [HIGH] latepoint/appointment_booking_plugin_βlatepoint|calendar&_scheduling_for_wordpress
1 CVE | CVSS 3.1: 9.1 | AAS 9.4
cpe:2.3:a:latepoint:appointment_booking_plugin_latepoint_calendar_scheduling_for_wordpress:*:*:*:*:*:*:*:*(< 5.7.1)
LatePoint Appointment Booking Plugin for WordPress versions up to and including 5.7.0 is affected by one high-severity vulnerability (CVSS 9.1). CVE-2026-92966 allows unauthenticated attackers to execute arbitrary shortcodes by exploiting insufficient input validation during the booking flow, potentially leading to significant compromise of the WordPress site without requiring any authentication.
Any organization running LatePoint for appointment scheduling on WordPress should treat this as urgent. Update the plugin beyond version 5.7.0 immediately, and review site logs for suspicious booking submissions that may indicate exploitation attempts. Consult the vendor advisory for technical details on the affected code path.
- π CVE-2026-92966 (CVSS 3.1: 9.1)