PT-2026-54942 · WordPress · Latepoint
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.6.3
Description
An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. This allows unauthenticated attackers to create approved bookings for services restricted to administrators and agents, which consumes restricted appointment capacity. The issue is exploitable through the
service id parameter via the params[booking][service id] parameter in the 'steps load step' endpoint and the presets[selected service] parameter in the 'steps start' endpoint.Recommendations
Update LatePoint – Calendar Booking Plugin for Appointments and Events to version 5.6.3 or later.
Restrict access to the 'steps load step' and 'steps start' endpoints to minimize the risk of unauthorized bookings.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint