PT-2026-107719 · Latepoint · Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress

·

CVE-2026-17538

·

Publicado

2026-10-07

·

Atualizado

2026-10-08

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process step customer() function using is user logged in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-17538

Produtos afetados

Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress