Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sorra

#55648of 57,633
4.3Total CVSS
Vulnerabilities · 1
PT-2026-95178
4.3
2026-09-17
WordPress · Latepoint · CVE-2026-18441
**Name of the Vulnerable Software and Affected Versions** LatePoint | Calendar & Scheduling for WordPress versions prior to 5.7.0 **Description** An Insecure Direct Object Reference (IDOR) exists in the `set customer object` function due to missing validation on a user-controlled key. This allows unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information, such as first name, last name, email address, and phone number, by iterating the `customer[id]` parameter. This issue is only exploitable when the site is configured with customer authentication disabled (guest checkout enabled). **Recommendations** Update LatePoint | Calendar & Scheduling for WordPress to version 5.7.0 or later. As a temporary mitigation, enable customer authentication to disable guest checkout.