PT-2026-107719 · Latepoint · Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress

·

CVE-2026-17538

·

Published

2026-10-07

·

Updated

2026-10-08

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process step customer() function using is user logged in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17538

Affected Products

Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress