CVE-2026-18441
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | 0 <= 5.6.9 |
Weaknesses
- CWE-639: CWE-639 Authorization Bypass Through User-Controlled Key
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d80ed885-43f8-43a4-bc61-e9ef92e3207e?source=cve
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/lib/helpers/steps_helper.php#L1184
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/lib/models/model.php#L574
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/lib/controllers/steps_controller.php#L341
- https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.9/latepoint.php#L1006
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.