Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Owlmind

#50894of 57,616
5.4Total CVSS
Vulnerabilities · 1
PT-2026-107719
5.4
2026-10-07
Latepoint · Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress · CVE-2026-17538
The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process step customer() function using is user logged in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset.