WordPress · Latepoint · CVE-2026-18441
**Name of the Vulnerable Software and Affected Versions**
LatePoint | Calendar & Scheduling for WordPress versions prior to 5.7.0
**Description**
An Insecure Direct Object Reference (IDOR) exists in the `set customer object` function due to missing validation on a user-controlled key. This allows unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information, such as first name, last name, email address, and phone number, by iterating the `customer[id]` parameter. This issue is only exploitable when the site is configured with customer authentication disabled (guest checkout enabled).
**Recommendations**
Update LatePoint | Calendar & Scheduling for WordPress to version 5.7.0 or later.
As a temporary mitigation, enable customer authentication to disable guest checkout.