{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-28T06:44:38.938","vulnerabilities":[{"cve":{"id":"CVE-2025-14873","sourceIdentifier":"security@wordfence.com","published":"2026-02-14T07:16:06.887","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without enforcing nonce verification. This makes it possible for unauthenticated attackers to perform multiple administrative actions via forged requests granted they can trick a site administrator into performing an action such as clicking on a link."},{"lang":"es","value":"El plugin LatePoint – Calendar Booking Plugin para Appointments and Events para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 5.2.5, inclusive. Esto se debe a que la función 'call_by_route_name' en la capa de enrutamiento solo valida las capacidades del usuario sin aplicar la verificación de nonce. Esto permite que atacantes no autenticados realicen múltiples acciones administrativas mediante peticiones falsificadas, siempre que puedan engañar a un administrador del sitio para que realice una acción, como hacer clic en un enlace."}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3449263/latepoint","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f7aa23c-ffa7-481b-8481-a36c7ed599d8?source=cve","source":"security@wordfence.com"}]}}]}