
CVE-2026-4785 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter… https://www.cve.org/CVERecord?id=CVE-2026-4785
Post summary
CVE-2026-4785 affects the LatePoint WordPress plugin, allowing stored XSS via the button_caption parameter; no PoC, exploit tools, active exploitation, or patch information is provided, but the technical details of the vulnerability are described.

