The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.
We have discovered 5,654 live websites that are affected by CVE-2026-11866.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5,654 live websites (97% of LatePoint install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 71 versions ( 93% of all versions) |
| 1,587 websites | |
| 568 websites | |
| 323 websites | |
| 298 websites | |
| 276 websites | |
| 266 websites | |
| 174 websites | |
| 155 websites | |
| 143 websites | |
| 137 websites |
| .com | 2,686 websites |
| .de | 236 websites |
| .org | 192 websites |
| .co.uk | 148 websites |
| .it | 147 websites |
| .nl | 144 websites |
| .fr | 123 websites |
| .net | 120 websites |
| .pl | 102 websites |
| .com.br | 91 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.com | *,*** | ||
| ***.tn | ***,*** | ||
| *********.com | ***,*** | ||
| ***************.com | ***,*** | ||
| ********.com | ***,*** | ||
| *****************.com | ***,*** | ||
| *******************.com | ***,*** | ||
| *******.***.***.mz | ***,*** | ||
| ********.co | ***,*** | ||
| *********.org | ***,*** |
FAQ