| **Product** | [LatePoint]( — Appointment Booking |
| **CWE** | [CWE-94]( — Code injection (shortcode execution) |
| **CVSS 3.1** | **9.1 Critical** (`AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N`) |
| **PoCbit catalog** | [ |
| **PoCbit page** | [ |
| **Verify marker** | `POCBIT-92966-OK` |
| **Advisory** | [Wordfence Threat Intel]( |
Python PoC aligned with [CVE-2026-102425](../CVE-2026-102425/poc.py): **mass exploit by default**, `--check`, `-u`, `--lab`, thread pool, `hits.txt` / `exploited.txt`. **No API key** — fully unauthenticated planting via the public booking flow.
WordPress **LatePoint** lets anonymous visitors book appointments. Customer **first name** / **last name** are stored with only `sanitize_text_field()` — square brackets are **not** stripped, so values like `[caption]…[/caption]` persist.
When the site renders the **Customer Cabinet** Gutenberg block (`render_customer_dashboard()` → `[latepoint_customer_dashboard]`), the dashboard template prints the customer name inside HTML (`Welcome %s` with `esc_html($customer->full_name)`). `esc_html` does **not** encode `[` or `]`, so shortcode-like payloads survive in the block output.
WordPress then runs **`do_shortcode` on `the_content` at priority 11**. Because **5.7.0** returned raw dashboard HTML from the shortcode handler, stored shortcodes in the welcome line were **parsed a second time** and executed. **5.7.1** fixes this by `encode_shortcode_delimiters()` on dashboard output (see `shortcodes_helper.php` : *"the_content runs do_shortcode at priority 11"*).
Impact: **unauthenticated arbitrary shortcode execution**. That is not always instant OS RCE by itself, but on a typical WordPress stack it chains to critical plugins (forms, builders, file managers, `eval`-backed shortcodes). The PoC proves execution with core **`[caption]`** and optional `POCBIT_EXEC_SHORTCODE` for site-specific RCE gadgets.
participant P as Page + Customer Cabinet block
participant WP as the_content do_shortcode
A->>B: first_name=[caption]PAYLOAD[/caption]
A->>P: GET customer dashboard (session/cookie)
P->>P: shortcode renders Welcome + payload
WP-->>A: executed shortcode output (marker)
1. **Plant** — Unauthenticated booking / customer step: set `customer[first_name]` (or `last_name`) to a shortcode payload.
2. **Trigger** — Load a page containing the **Customer Cabinet** block while authenticated as that customer (guest session after booking, or login). Second `do_shortcode` pass fires.
- `lib/models/customer_model.php` — `prepare_data_before_it_is_set()` / `sanitize_text_field` on names
- `lib/views/customer_cabinet/dashboard.php` — welcome line with `full_name`
- `lib/helpers/blocks_helper.php` — `render_customer_dashboard()`
- **Fix:** `lib/helpers/shortcodes_helper.php` (5.7.1) — `encode_shortcode_delimiters()`
| `poc.py` | CLI, interactive , **mass exploit** |
| `_engine.py` | Version check, booking plant attempt, dashboard trigger, lab |
| `up.php` | Optional probe file if your RCE shortcode drops files |
| `targets.example.txt` | URL list for bulk |
| `extract-5.7.0/` / `extract-5.7.1/` | Vendor trees for diff (optional) |
python poc.py fofa_latepoint.txt -t 20 -T 28
Fingerprint: `readme.txt` **Stable tag**, LatePoint front-end hints (`latepoint-book-form`, `latepoint_helper`), version ≤ 5.7.0.
python poc.py -u --check
If the target has a dangerous shortcode (file manager, etc.):
set POCBIT_EXEC_SHORTCODE=[your_shortcode_here]
Or: `python poc.py -u URL --exec-shortcode "[shortcode]"`
Default probe uses WordPress core **`[caption]POCBIT-92966-OK[/caption]`** (no extra plugins required to prove execution).
Binds `127.0.0.1:8797`, simulates readme **5.7.0**, booking plant, and double `do_shortcode` on dashboard HTML. Expect `"exploited": true`.
| `affected` | Version ≤ 5.7.0 (check mode) |
| `exploited` | Marker after booking wizard + logged-in Customer Cabinet page |
| `plant_no_auth_cookie` | Name planted but no customer/WP login cookie from `admin-ajax` |
| `plant_missing_service_id` | Booking wizard has no public services to select |
| `plant_otp_required` / `plant_auth_blocked` | Customer step blocked by OTP or login policy |
| `no_customer_cabinet_page` | Session OK but no `[latepoint_customer_dashboard]` page found |
| `shortcode_not_triggered` | Plant + session OK; cabinet loaded but marker not executed |
Exploit success rate depends on: booking wizard reachable without payment, Customer Cabinet block published, guest session after booking.
1. Upgrade LatePoint to **≥ 5.7.1** immediately.
2. Remove or restrict public booking if not required.
3. WAF rule: block `[` in `customer[first_name]` / `last_name` on `latepoint_route_call` — temporary only.
4. Audit customer records for bracket characters in names.
## GitHub repository Description (copy/paste)
CVE-2026-92966 — WordPress LatePoint ≤5.7.0 unauthenticated stored shortcode execution (CVSS 9.1, CWE-94). PoCbit mass-exploit PoC: plant [caption]/custom shortcode in booking first name → Customer Cabinet block double do_shortcode; fixed in 5.7.1. No API key. check/exploit/mass, hits.txt & exploited.txt, --lab. Marker: POCBIT-92966-OK.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
