PT-2026-95283 · WordPress · Latepoint
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LatePoint – Calendar Booking Plugin for Appointments and Events versions prior to 5.6.4
Description
An Insecure Direct Object Reference (IDOR) exists in the
LatePointAbilityDeleteBooking::execute function due to missing validation on a user-controlled key. Attackers with LatePoint Agent-level access or higher can read bookings and customer personally identifiable information (PII), including full names, emails, phone numbers, and notes assigned to other agents. Additionally, they can delete arbitrary bookings by providing any booking ID. This issue is only exploitable if an administrator has enabled the Abilities API toggles latepoint abilities api, latepoint abilities api delete, and/or latepoint abilities api edit in the plugin settings.Recommendations
Update the plugin to version 5.6.4 or later.
Disable the
latepoint abilities api, latepoint abilities api delete, and latepoint abilities api edit toggles in the plugin settings as a temporary mitigation.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint